Loading vulnerability details…
CVSS v3.1
6.5
CVSS v4.0
7.1
EPSS
0.27%
Published
Feb 10, 2026
Modified
Feb 25, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HWeaknesses (CWE)
Affected Products (3)
References (1)