CVE-2026-1850: An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification

Published Feb 10, 2026
·
Updated

Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.

Affected Software

3 affected components
mongodb/mongodb
MongoDB MongoDB>=8.0.0<8.0.18
MongoDB MongoDB>=8.2.0<8.2.4

Event History

Feb 10, 2026
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-1850?

CVE-2026-1850 is classified as a high-severity vulnerability due to its potential to allow an authorized user to disable the MongoDB server.

2

How do I fix CVE-2026-1850?

To fix CVE-2026-1850, ensure you are using the latest version of MongoDB that includes security patches addressing this vulnerability.

3

Who is affected by CVE-2026-1850?

CVR-2026-1850 affects authorized users of MongoDB who can execute complex queries.

4

What type of issues can CVE-2026-1850 cause?

CVE-2026-1850 can lead to excessive memory usage in the MongoDB Query Planner, potentially resulting in an Out-Of-Memory crash.

5

Is CVE-2026-1850 a coding issue?

CVE-2026-1850 arises from the handling of boolean expressions in complex queries, making it a design and implementation issue within the MongoDB Query Planner.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203