CVE-2026-8202

Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-120668 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

18 May 2026, 12:55

Type Values Removed Values Added
First Time Mongodb mongodb
Mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
References () https://jira.mongodb.org/browse/SERVER-120668 - () https://jira.mongodb.org/browse/SERVER-120668 - Issue Tracking, Vendor Advisory

13 May 2026, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 04:17

Updated : 2026-05-18 12:55


NVD link : CVE-2026-8202

Mitre link : CVE-2026-8202

CVE.ORG link : CVE-2026-8202


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-770

Allocation of Resources Without Limits or Throttling