VYPR
Medium severity6.4NVD Advisory· Published Mar 17, 2026· Updated Apr 2, 2026

CVE-2026-4358

CVE-2026-4358

Description

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

Affected products

1
  • cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
    Range: >=7.0.0,<7.0.31

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

4