CVE-2026-1849Uncontrolled Recursion in INC Mongodb Server

Severity
7.1HIGHNVD
EPSS
0.1%
top 83.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5mongodb_inc/mongodb_server8.08.0.18+2
NVDmongodb/mongodb7.0.07.0.29+2

🔴Vulnerability Details

3
CVEList
Mongod can run out of stack memory when expressions create deeply nested documents2026-02-10
GHSA
GHSA-cf58-vmg8-228p: MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents2026-02-10
OSV
CVE-2026-1849: MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-1849 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-1849 — Uncontrolled Recursion | cvebase