CVE-2026-9737: MongoDB

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.

Affected products

  • MongoDB MongoDB: from 7.0.0, before 7.0.39 (fixed in 7.0.39); from 8.0.0, before 8.0.28 (fixed in 8.0.28); from 8.2.0, up to and including 8.2.12; from 8.3.0, before 8.3.7 (fixed in 8.3.7); version 9.0.0 only; version 9.1.0 only

Published 2026-07-22. Last modified 2026-09-30.