Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppxc-fr36-g8v9

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.

EPSS

Процентиль: 19%
0.0027
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.

CVSS3: 6.5
nvd
около 2 месяцев назад

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.

CVSS3: 6.5
debian
около 2 месяцев назад

This issue can occur when running an aggregation pipeline that uses th ...

EPSS

Процентиль: 19%
0.0027
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-617