CVE-2020-7929: MongoDB

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.

Affected products

  • MongoDB MongoDB: from 3.6.0, before 3.6.21 (fixed in 3.6.21); from 4.0.0, before 4.0.20 (fixed in 4.0.20)

Published 2021-03-01. Last modified 2026-06-17.