When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated clients, leading to pre-auth denial-of-service in affected product configurations.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-124183 |
Configurations
No configuration.
History
09 Jun 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 23:17
Updated : 2026-06-09 23:17
NVD link : CVE-2026-9742
Mitre link : CVE-2026-9742
CVE.ORG link : CVE-2026-9742
JSON object : View
Products Affected
No product.
CWE
CWE-1287
Improper Validation of Specified Type of Input
