VYPR
Medium severity6.5NVD Advisory· Published Feb 10, 2026· Updated Jun 17, 2026

CVE-2026-1849

CVE-2026-1849

Description

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • MongoDB/Serverllm-fuzzy
  • MongoDB Inc/MongoDB Serverv5
    Range: 8.0
  • MongoDB/MongoDB2 versions
    cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.29
    • (no CPE)
  • osv-coords
    Range: >= 7.0.0, < 7.0.29

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.