MongoDB Server
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*
- >= 6.0, < 6.0.21
- >= 7.0, < 7.0.17
- >= 8.0, < 8.0.5
A stack overflow vulnerability has been identified in MongoDB Server's JSON parsing mechanism. This issue allows specifically crafted JSON inputs to create excessive recursion, consuming large amounts of stack space and causing the server to crash. The vulnerability can be exploited pre-authentication. It affects MongoDB Server versions 7.0 prior to 7.0.17, 8.0 prior to 8.0.5, and 6.0 prior to 6.0.21, with the latter requiring authentication for exploitation.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the MongoDB server.
Users can upgrade to MongoDB Server versions 8.0.5, 7.0.17, or 6.0.21 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.