A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.
{
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.2"
},
{
"fixed": "8.2.6"
},
{
"introduced": "8.0"
},
{
"fixed": "8.0.20"
},
{
"introduced": "7.0"
},
{
"fixed": "7.0.31"
}
]
}
],
"cwe_ids": [
"CWE-416"
],
"cna_assigner": "mongodb",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4148.json"
}{
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"cpe": [
"cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
"cpe:2.3:a:mongodb:mongodb:8.3.0:alpha0:*:*:-:*:*:*",
"cpe:2.3:a:mongodb:mongodb:8.3.0:alpha1:*:*:-:*:*:*",
"cpe:2.3:a:mongodb:mongodb:8.3.0:alpha2:*:*:-:*:*:*",
"cpe:2.3:a:mongodb:mongodb:8.3.0:alpha3:*:*:-:*:*:*",
"cpe:2.3:a:mongodb:mongodb:8.3.0:rc1:*:*:-:*:*:*"
],
"extracted_events": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.31"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.20"
},
{
"introduced": "8.2.0"
},
{
"fixed": "8.2.6"
},
{
"introduced": "8.3.0-alpha0"
},
{
"last_affected": "8.3.0-alpha0"
},
{
"introduced": "8.3.0-alpha1"
},
{
"last_affected": "8.3.0-alpha1"
},
{
"introduced": "8.3.0-alpha2"
},
{
"last_affected": "8.3.0-alpha2"
},
{
"introduced": "8.3.0-alpha3"
},
{
"last_affected": "8.3.0-alpha3"
},
{
"introduced": "8.3.0-rc1"
},
{
"last_affected": "8.3.0-rc1"
}
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4148.json"
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"212916051933611333336019566765871154533",
"127072531193682496647404363037825275968",
"82618083542634382065142722552922596523",
"4324924340243736427572372707787432252"
]
},
"target": {
"file": "src/mongo/util/md5.cpp"
},
"source": "https://github.com/mongodb/mongo/commit/32a732a9b646200050bedd569d0e18fda534f92c",
"signature_version": "v1",
"id": "CVE-2026-4148-074a18d5",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"243049191849363753065600341015684019120",
"312131738472726656287569917628189519640",
"269011836439409954144825691130893251414",
"261701652252642430706775392390697022443"
]
},
"target": {
"file": "src/mongo/util/md5.cpp"
},
"source": "https://github.com/mongodb/mongo/commit/05009bb976757189fd9bff4cebc5d803a6737a95",
"signature_version": "v1",
"id": "CVE-2026-4148-1abd9456",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "22528191371751663195701634984920870034",
"length": 244.0
},
"target": {
"function": "md5_init",
"file": "src/mongo/util/md5.cpp"
},
"source": "https://github.com/mongodb/mongo/commit/05009bb976757189fd9bff4cebc5d803a6737a95",
"signature_version": "v1",
"id": "CVE-2026-4148-3141a725",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "253896680426164393151009864932457722232",
"length": 57.0
},
"target": {
"function": "md5_init_state",
"file": "src/mongo/util/md5.cpp"
},
"source": "https://github.com/mongodb/mongo/commit/32a732a9b646200050bedd569d0e18fda534f92c",
"signature_version": "v1",
"id": "CVE-2026-4148-de078695",
"deprecated": false
}
]
"2026-08-12T16:24:13Z"