CVE-2018-20805: MongoDB

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This issue affects MongoDB Server v4.0 versions prior to 4.0.5 and MongoDB Server v3.6 versions prior to 3.6.10.

Affected products

  • MongoDB MongoDB: from 3.6.0, before 3.6.10 (fixed in 3.6.10); from 4.0.0, before 4.0.5 (fixed in 4.0.5)

Published 2020-11-23. Last modified 2026-06-17.