A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.
{
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11933.json",
"cna_assigner": "mongodb",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.3.0"
},
{
"last_affected": "8.3.3"
},
{
"introduced": "8.2.0"
},
{
"last_affected": "8.2.10"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.0.25"
},
{
"introduced": "7.0.0"
},
{
"last_affected": "7.0.36"
},
{
"introduced": "6.0"
},
{
"last_affected": "6.0.28"
},
{
"introduced": "5.0"
},
{
"last_affected": "5.0.33"
},
{
"introduced": "4.4.0"
},
{
"last_affected": "4.4.30"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
"extracted_events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.31"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.34"
},
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.29"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.37"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.26"
},
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.11"
},
{
"introduced": "8.3.0"
},
{
"fixed": "8.3.4"
}
],
"source": "CPE_RANGE"
}
"2026-07-22T00:25:31Z"
[
{
"id": "CVE-2026-11933-1e816e42",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/cfe43bb3f7ade50c4ee108dfc329d6d4d3318b41",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-56814532",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/3173cdbda3516e78038bceee2fc818a533f36be5",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-63340732",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/a820e42c7df1381abd963332bd157abe76efe4e6",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-679d3af9",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/cfe43bb3f7ade50c4ee108dfc329d6d4d3318b41",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-67f30c83",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/feca9bec037cc018d9b398a30e7bc8ab22d4aa2b",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-773e350e",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/3173cdbda3516e78038bceee2fc818a533f36be5",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-83551513",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/ec6cf1afb7921a56e14e2a13cd51781a3c8ebbb1",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-85b66219",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/e218b5151154a32364397c2c00c3f806d68e83ba",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/common/types/bson.cpp"
}
},
{
"id": "CVE-2026-11933-907e6df2",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/33f30ee3b0d8525f8ee409ead1e3b847bfb1eac1",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-93e53df5",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/e218b5151154a32364397c2c00c3f806d68e83ba",
"target": {
"file": "src/mongo/scripting/mozjs/common/types/bson.cpp"
}
},
{
"id": "CVE-2026-11933-a87343d8",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/feca9bec037cc018d9b398a30e7bc8ab22d4aa2b",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-c939ae40",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 441.0,
"function_hash": "295057127057894248814892708121671128514"
},
"source": "https://github.com/mongodb/mongo/commit/33f30ee3b0d8525f8ee409ead1e3b847bfb1eac1",
"target": {
"function": "BSONInfo::Functions::bsonObjToArray::call",
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-db2ba4c6",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/a820e42c7df1381abd963332bd157abe76efe4e6",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
},
{
"id": "CVE-2026-11933-fb234fce",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267529282098735039366978343079896535491",
"138471549822277084035973327391447184028",
"299058178306114286905631751467214684356",
"208586406495904219825796642023962444750"
]
},
"source": "https://github.com/mongodb/mongo/commit/ec6cf1afb7921a56e14e2a13cd51781a3c8ebbb1",
"target": {
"file": "src/mongo/scripting/mozjs/bson.cpp"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11933.json"