After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.
This issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.
{
"cna_assigner": "mongodb",
"cwe_ids": [
"CWE-416"
],
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.2"
},
{
"fixed": "8.2.9"
},
{
"introduced": "8.3"
},
{
"fixed": "8.3.2"
}
]
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8336.json"
}"2026-07-22T01:09:33Z"
[
{
"target": {
"function": "Obj::search",
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"length": 988.0,
"function_hash": "17181056965332531028681155129851284942"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-08ad15c4",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"line_hashes": [
"65317806234226920521720845331578521082",
"245205739251347437876425597495755876481",
"109749818435937265218130737097210075244",
"247724741587646782412887786320692163933",
"328299337808136919563643867456051799671",
"168020673177810988486900283615589649830",
"170052273858241919648121125823866015059",
"177147919177640274616929074969145590120",
"140861398997613641900615087528359816369",
"294172095836668649572112064188327133592",
"103431700251158212873865689548307615353",
"21787099695343064233815986318428483963",
"157562864901160561707888628653518219141",
"250504151046058816035709411326397744704"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-3797dc56",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
},
"digest": {
"line_hashes": [
"292572099948037041716578539154433823516",
"168860491958264251483141325059901754282",
"304117868208266248508117415656816929694",
"179593579132299061605021834936400112936"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-3d904649",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"function": "Obj::insert",
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"length": 1050.0,
"function_hash": "70226459102367042737321538611145560590"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-46a07206",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
},
"digest": {
"line_hashes": [
"291363120804310266702293571491914596809",
"33869876076183871238703932409763090783"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-55c6a28a",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"function": "MeasurementMap::insertOne",
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
},
"digest": {
"length": 579.0,
"function_hash": "43553138671068495841916643857804982519"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-573b1c19",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"function": "MeasurementMap::insertOne",
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
},
"digest": {
"length": 599.0,
"function_hash": "284460113755408055723012211659961360780"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-7b34e191",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"line_hashes": [
"65317806234226920521720845331578521082",
"245205739251347437876425597495755876481",
"109749818435937265218130737097210075244",
"247724741587646782412887786320692163933",
"328299337808136919563643867456051799671",
"168020673177810988486900283615589649830",
"170052273858241919648121125823866015059",
"177147919177640274616929074969145590120",
"140861398997613641900615087528359816369",
"294172095836668649572112064188327133592",
"103431700251158212873865689548307615353",
"21787099695343064233815986318428483963",
"157562864901160561707888628653518219141",
"250504151046058816035709411326397744704"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-a00600ff",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
},
"digest": {
"line_hashes": [
"220012559814535802246991203699235448665",
"292813745953450357917782590991431684195",
"151782744504930929400284312418396007787"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-ac57b75a",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
},
"digest": {
"line_hashes": [
"291363120804310266702293571491914596809",
"33869876076183871238703932409763090783"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-ae8682c1",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"function": "Obj::search",
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"length": 988.0,
"function_hash": "17181056965332531028681155129851284942"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-b20f3e14",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
},
"digest": {
"line_hashes": [
"113590516626605239294940485100571288810",
"200762295114800290845951546202029883764",
"268316385711008539282353089121521072588",
"184940241524942480541267925278565633866",
"57908861127480025164680135191487105877",
"22008568524960951903435505329165604572",
"283531283680862789255620472702442978052"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-b7e9811b",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
},
{
"target": {
"file": "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
},
"digest": {
"line_hashes": [
"189988079331693010828710016868224288344",
"156644622417418443415807260198870532652",
"127287703221177560262489158943077347278",
"238171269685132529499568082580439161603",
"5099464907976194915440695461937409677",
"12579336589641520520804530894688239105",
"9615073687642051710079005079633121505",
"128352877459597030677197941825486183445",
"73863290553960507209707682947063567550",
"191257911512827898256694559820641371502",
"127277178768055444847121840322197792737"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-8336-ca202f9e",
"source": "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0"
},
{
"target": {
"function": "Obj::insert",
"file": "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
},
"digest": {
"length": 1066.0,
"function_hash": "221304163357851772164061278326293544638"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-8336-dd5b676f",
"source": "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json"