Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-130110 |
|
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance. | |
| Title | Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-08-11T20:29:08.509Z
Reserved: 2026-08-03T15:53:33.908Z
Link: CVE-2026-18697
Updated: 2026-08-11T20:29:04.605Z
Status : Received
Published: 2026-08-11T19:17:23.983
Modified: 2026-08-11T21:17:32.333
Link: CVE-2026-18697
No data.
OpenCVE Enrichment
No data.
-
CWE-617
Reachable Assertion