CVE-2026-8336

Source
https://cve.org/CVERecord?id=CVE-2026-8336
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8336
Aliases
Downstream
Published
2026-05-13T00:16:16.568Z
Modified
2026-07-22T01:09:33.987499Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:M/U:Red CVSS Calculator
Summary
Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands
Details

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.

This issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-416"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "8.2"
                },
                {
                    "fixed": "8.2.9"
                },
                {
                    "introduced": "8.3"
                },
                {
                    "fixed": "8.3.2"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8336.json"
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.2.0"
        },
        {
            "fixed": "8.2.9"
        },
        {
            "introduced": "8.3.0"
        },
        {
            "fixed": "8.3.2"
        }
    ]
}

Affected versions

r8.*
r8.2.0
r8.2.1
r8.2.1-rc0
r8.2.1-rc1
r8.2.2
r8.2.2-rc0
r8.2.3-alpha0
r8.2.4-alpha0
r8.2.4-alpha1
r8.3.0
r8.3.1

Database specific

vanir_signatures_modified
"2026-07-22T01:09:33Z"
vanir_signatures
[
    {
        "target": {
            "function": "Obj::search",
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "length": 988.0,
            "function_hash": "17181056965332531028681155129851284942"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-08ad15c4",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "line_hashes": [
                "65317806234226920521720845331578521082",
                "245205739251347437876425597495755876481",
                "109749818435937265218130737097210075244",
                "247724741587646782412887786320692163933",
                "328299337808136919563643867456051799671",
                "168020673177810988486900283615589649830",
                "170052273858241919648121125823866015059",
                "177147919177640274616929074969145590120",
                "140861398997613641900615087528359816369",
                "294172095836668649572112064188327133592",
                "103431700251158212873865689548307615353",
                "21787099695343064233815986318428483963",
                "157562864901160561707888628653518219141",
                "250504151046058816035709411326397744704"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-3797dc56",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        },
        "digest": {
            "line_hashes": [
                "292572099948037041716578539154433823516",
                "168860491958264251483141325059901754282",
                "304117868208266248508117415656816929694",
                "179593579132299061605021834936400112936"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-3d904649",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "function": "Obj::insert",
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "length": 1050.0,
            "function_hash": "70226459102367042737321538611145560590"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-46a07206",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
        },
        "digest": {
            "line_hashes": [
                "291363120804310266702293571491914596809",
                "33869876076183871238703932409763090783"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-55c6a28a",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "function": "MeasurementMap::insertOne",
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        },
        "digest": {
            "length": 579.0,
            "function_hash": "43553138671068495841916643857804982519"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-573b1c19",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "function": "MeasurementMap::insertOne",
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        },
        "digest": {
            "length": 599.0,
            "function_hash": "284460113755408055723012211659961360780"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-7b34e191",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "line_hashes": [
                "65317806234226920521720845331578521082",
                "245205739251347437876425597495755876481",
                "109749818435937265218130737097210075244",
                "247724741587646782412887786320692163933",
                "328299337808136919563643867456051799671",
                "168020673177810988486900283615589649830",
                "170052273858241919648121125823866015059",
                "177147919177640274616929074969145590120",
                "140861398997613641900615087528359816369",
                "294172095836668649572112064188327133592",
                "103431700251158212873865689548307615353",
                "21787099695343064233815986318428483963",
                "157562864901160561707888628653518219141",
                "250504151046058816035709411326397744704"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-a00600ff",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
        },
        "digest": {
            "line_hashes": [
                "220012559814535802246991203699235448665",
                "292813745953450357917782590991431684195",
                "151782744504930929400284312418396007787"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-ac57b75a",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
        },
        "digest": {
            "line_hashes": [
                "291363120804310266702293571491914596809",
                "33869876076183871238703932409763090783"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-ae8682c1",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "function": "Obj::search",
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "length": 988.0,
            "function_hash": "17181056965332531028681155129851284942"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-b20f3e14",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
        },
        "digest": {
            "line_hashes": [
                "113590516626605239294940485100571288810",
                "200762295114800290845951546202029883764",
                "268316385711008539282353089121521072588",
                "184940241524942480541267925278565633866",
                "57908861127480025164680135191487105877",
                "22008568524960951903435505329165604572",
                "283531283680862789255620472702442978052"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-b7e9811b",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    },
    {
        "target": {
            "file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        },
        "digest": {
            "line_hashes": [
                "189988079331693010828710016868224288344",
                "156644622417418443415807260198870532652",
                "127287703221177560262489158943077347278",
                "238171269685132529499568082580439161603",
                "5099464907976194915440695461937409677",
                "12579336589641520520804530894688239105",
                "9615073687642051710079005079633121505",
                "128352877459597030677197941825486183445",
                "73863290553960507209707682947063567550",
                "191257911512827898256694559820641371502",
                "127277178768055444847121840322197792737"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8336-ca202f9e",
        "source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
    },
    {
        "target": {
            "function": "Obj::insert",
            "file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        },
        "digest": {
            "length": 1066.0,
            "function_hash": "221304163357851772164061278326293544638"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8336-dd5b676f",
        "source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json"