Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9753 | 8.1 HIGH | Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. |
| CVE-2026-9740 | 7.5 HIGH | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow |
| CVE-2026-9742 | 7.5 HIGH | Authenticate command with specific mechanism parameter can trigger server crash |
| CVE-2026-9750 | 6.5 MEDIUM | Metadata name collision on $-prefixed fields causes post-auth server crash |
| CVE-2026-9748 | 6.5 MEDIUM | $_internalConvertBucketIndexStats may crash the mongod server when working on no timeserie |
| CVE-2026-9747 | 6.5 MEDIUM | Crafted cross-shard merge aggregation crashes MongoDB Server |
| CVE-2026-9741 | 6.5 MEDIUM | Client side encryption fails to encrypt values in a $vectorSearch |
| CVE-2026-9749 | 6.5 MEDIUM | Using MaxKey() may crash the server |
| CVE-2026-9752 | 6.5 MEDIUM | GeometryCollection with strict-winding polygon causes server crash during 2dsphere index k |
| CVE-2026-9746 | 6.5 MEDIUM | Server crashes in case of the use of exchange |
| CVE-2026-9743 | 6.5 MEDIUM | Aggregation sub-pipeline null dereference may allow DoS via crafted getMore |
| CVE-2026-9751 | 5.5 MEDIUM | Sensitive data could be written to mongod.log |
| CVE-2026-9735 | 5.5 MEDIUM | Keyfile contents are in MongoDB Server logs |
No comments yet