GHSA-w3fp-8cx4-8vqpMediumCVSS 5.3

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by...

Published
July 22, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (1)

📋 Description

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.

🔗 References (3)