Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-9740

MongoDB Server: unbounded recursion in BSON validation lets an unauthenticated client crash mongod

Technology

MongoDB

CVSS Score

7.5 / 10.0

Affected Versions

8.3 before 8.3.3; 8.2 before 8.2.10; 8.0 before 8.0.24; 7.0 before 7.0.35

Upstream Fix

8.3.3; 8.2.10; 8.0.24; 7.0.35

Published

June 9, 2026

OSSeva Coverage

Fixed upstream

Description

MongoDB Server's BSON validator allows uncontrolled mutual recursion between validation functions when handling certain nested binary data structures, because each re-entry resets the depth tracking. An unauthenticated user can crash mongod with a specially crafted message. Tracked as SERVER-125063. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.3 before 8.3.3; 8.2 before 8.2.10; 8.0 before 8.0.24; 7.0 before 7.0.35, you need this patch. Book a discovery call to get covered.