Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9753

Опубликовано: 09 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия до 7.0.35 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия от 8.0.0 (включая) до 8.0.24 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия от 8.2.0 (включая) до 8.2.10 (исключая)
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Версия от 8.3.0 (включая) до 8.3.3 (исключая)

EPSS

Процентиль: 22%
0.00298
Низкий

8.1 High

CVSS3

Дефекты

CWE-1287
CWE-787

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 месяцев назад

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

CVSS3: 8.1
debian
около 2 месяцев назад

The $_internalApplyOplogUpdate aggregation pipeline stage can be used ...

CVSS3: 8.1
github
около 2 месяцев назад

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.

EPSS

Процентиль: 22%
0.00298
Низкий

8.1 High

CVSS3

Дефекты

CWE-1287
CWE-787