CVE-2026-82075: Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service
An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to expend CPU resources without any rate limiting, degrading or denying service to legitimate clients. No authentication, elevated privileges, or user interaction is required. Only availability is affected; data confidentiality and integrity are not impacted.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
MongoDB sharded-cluster router processes are exposed when their router port is reachable by a client. The described attack does not require the client to authenticate.
What does an attacker need to exploit this issue?
An attacker needs only network access to a router port and the ability to send connection-monitoring parameters. No credentials, elevated privileges, or user interaction are required.
What is the expected impact of exploitation?
The attacker can cause the router to consume CPU without rate limiting, degrading service or denying service to legitimate clients. The provided data indicates availability impact only, with no confidentiality or integrity impact.