216.73.217.80

CVE-2026-9752

· Published 09/06/2026 23:17 · Modified 10/06/2026 19:43

Labels: CVE-2026-9752 2026-06-09CVE-2026-9752CWE-476[email protected]

Essential information

Published
09/06/2026 23:17
Modified
10/06/2026 19:43
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongodb cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

References