A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query.
This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-122032 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 May 2026, 22:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jira.mongodb.org/browse/SERVER-122032 - Issue Tracking, Vendor Advisory | |
| First Time |
Mongodb mongodb
Mongodb |
|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
13 May 2026, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 04:17
Updated : 2026-05-13 22:50
NVD link : CVE-2026-8201
Mitre link : CVE-2026-8201
CVE.ORG link : CVE-2026-8201
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-416
Use After Free
