216.73.217.80

CVE-2026-9748

· Published 09/06/2026 23:17 · Modified 10/06/2026 19:43

Labels: CVE-2026-9748 2026-06-09CVE-2026-9748CWE-617[email protected]

Essential information

Published
09/06/2026 23:17
Modified
10/06/2026 19:43
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechanism, but rather a TeeBuffer-internal signal used solely by $facet to coordinate its sub-pipelines. When this stage is placed before $facet in a pipeline, TeeBuffer receives the unexpected PauseExecution from upstream and hits a hard invariant assertion, crashing mongod.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongod cpe:2.3:a:mongodb:mongod:*:*:*:*:*:*:*:*

References