CVE-2026-9743 HIGH

CVE-2026-9743: Aggregation sub-pipeline null dereference may allow DoS via crafted getMore

Vendor Mongodb
Product MongoDB server
Weakness CWE-476
Published June 9, 2026
Last update June 10, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may dereference this null sub-pipeline when reattaching to the operation context, accessing an invalid address and crashing the process. This issue allows an authenticated user who can run aggregation pipelines to cause a denial of service by issuing a specially crafted aggregation followed by getMore on affected versions.

Key dates

02Disclosure timeline

June 9, 2026 CVE published
June 10, 2026 Record updated