Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-128125 |
|
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb |
|
| Vendors & Products |
Mongodb
Mongodb mongodb |
Fri, 12 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash. | |
| Title | Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-06-13T03:55:46.393Z
Reserved: 2026-06-10T18:54:51.125Z
Link: CVE-2026-11933
Updated: 2026-06-12T13:28:39.655Z
Status : Awaiting Analysis
Published: 2026-06-12T02:16:38.527
Modified: 2026-06-12T16:06:17.027
Link: CVE-2026-11933
No data.
OpenCVE Enrichment
Updated: 2026-06-12T03:30:12Z