Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-25611

MongoDB Server: pre-authentication memory exhaustion

Technology

MongoDB

CVSS Score

7.5 / 10.0

Affected Versions

8.2 before 8.2.4; 8.0 before 8.0.18; 7.0 before 7.0.29

Upstream Fix

8.2.4; 8.0.18; 7.0.29

Published

February 10, 2026

OSSeva Coverage

Fixed upstream

Description

A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server. Tracked as SERVER-116210. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.2 before 8.2.4; 8.0 before 8.0.18; 7.0 before 7.0.29, you need this patch. Book a discovery call to get covered.