CVE-2026-82063: MongoDB

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing conditions during cursor operations, a stale pointer to a freed resource may be retained and subsequently dereferenced during cursor cleanup, leading to a server process crash.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.41 (fixed in 7.0.41); from 8.0.0, before 8.0.30 (fixed in 8.0.30); from 8.3.0, before 8.3.9 (fixed in 8.3.9)

Published 2026-09-08. Last modified 2026-09-16.