This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-122032 |
|
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Mongodb mongodb Server |
Wed, 13 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2. | |
| Title | Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-05-13T14:34:27.091Z
Reserved: 2026-05-08T23:42:58.650Z
Link: CVE-2026-8201
Updated: 2026-05-13T14:34:23.109Z
Status : Undergoing Analysis
Published: 2026-05-13T04:17:41.870
Modified: 2026-05-13T15:34:29.847
Link: CVE-2026-8201
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:35:08Z