CVE-2019-2392: MongoDB
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to overflow negative values. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.
Affected products
- MongoDB MongoDB: from 3.6.0, before 3.6.20 (fixed in 3.6.20); from 4.0.0, before 4.0.20 (fixed in 4.0.20); from 4.2.0, before 4.2.9 (fixed in 4.2.9); from 4.4.0, before 4.4.1 (fixed in 4.4.1)
Published 2020-11-23. Last modified 2026-06-17.