CVE-2024-8654: MongoDB
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.
Affected products
- MongoDB MongoDB: from 6.0.0, up to and including 6.0.3
Published 2024-09-10. Last modified 2026-06-17.