Medium severity5.4NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2021-32036
CVE-2021-32036
Description
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- MongoDB Inc./MongoDB Serverv5Range: 5.0
Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-59294nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.