Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-125063 |
|
Mon, 15 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb mongodb
|
|
| CPEs | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mongodb mongodb
|
Wed, 10 Jun 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Server |
Tue, 09 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking. | |
| Title | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-06-10T18:16:38.879Z
Reserved: 2026-05-27T17:33:16.187Z
Link: CVE-2026-9740
No data.
Status : Analyzed
Published: 2026-06-09T23:17:03.437
Modified: 2026-06-15T16:55:47.097
Link: CVE-2026-9740
No data.
OpenCVE Enrichment
Updated: 2026-06-10T02:30:05Z