CVE-2026-82052: $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars

Published Sep 8, 2026
·
Updated

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.

Affected Software

1 affected component
MongoDB mongod

Event History

Sep 8, 2026
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

MongoDB deployments are exposed if authenticated users can run aggregation pipeline stages. The described impact is a crash of the mongod server, resulting in an availability risk.

2

What does an attacker need to trigger the crash?

An attacker needs valid authentication and permission to run aggregation pipeline stages. Exploitation also depends on constructing a $regexFindAll match that begins in the middle of a multi-code-unit UTF-8 character under the specific conditions described.

3

Is a default MongoDB deployment known to be affected?

The available information does not state whether default configurations permit the required aggregation activity. Exposure depends on whether authenticated users have the ability to run aggregation pipeline stages.

4

What can be done if patching is not immediately possible?

Restrict aggregation pipeline execution for authenticated users who do not require it, particularly access to queries using $regexFindAll. This reduces the set of users able to submit the input needed to trigger the assertion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203