CVE-2026-8336

Source
https://cve.org/CVERecord?id=CVE-2026-8336
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8336
Aliases
Downstream
Published
2026-05-13T00:16:16Z
Modified
2026-08-12T16:09:25Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:M/U:Red CVSS Calculator
Summary
Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands
Details

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.

This issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

Database specific
{
    "cna_assigner":  "mongodb",
    "cwe_ids":  [
        "CWE-416"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8336.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "8.2"
                },
                {
                    "fixed":  "8.2.9"
                },
                {
                    "introduced":  "8.3"
                },
                {
                    "fixed":  "8.3.2"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "8.2.0"
        },
        {
            "fixed":  "8.2.9"
        },
        {
            "introduced":  "8.3.0"
        },
        {
            "fixed":  "8.3.2"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

r8.*
r8.2.0
r8.2.1
r8.2.1-rc0
r8.2.1-rc1
r8.2.2
r8.2.2-rc0
r8.2.3-alpha0
r8.2.4-alpha0
r8.2.4-alpha1
r8.3.0
r8.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "17181056965332531028681155129851284942",
            "length":  988
        },
        "id":  "CVE-2026-8336-08ad15c4",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp",
            "function":  "Obj::search"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "65317806234226920521720845331578521082",
                "245205739251347437876425597495755876481",
                "109749818435937265218130737097210075244",
                "247724741587646782412887786320692163933",
                "328299337808136919563643867456051799671",
                "168020673177810988486900283615589649830",
                "170052273858241919648121125823866015059",
                "177147919177640274616929074969145590120",
                "140861398997613641900615087528359816369",
                "294172095836668649572112064188327133592",
                "103431700251158212873865689548307615353",
                "21787099695343064233815986318428483963",
                "157562864901160561707888628653518219141",
                "250504151046058816035709411326397744704"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-3797dc56",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "292572099948037041716578539154433823516",
                "168860491958264251483141325059901754282",
                "304117868208266248508117415656816929694",
                "179593579132299061605021834936400112936"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-3d904649",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "70226459102367042737321538611145560590",
            "length":  1050
        },
        "id":  "CVE-2026-8336-46a07206",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp",
            "function":  "Obj::insert"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "291363120804310266702293571491914596809",
                "33869876076183871238703932409763090783"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-55c6a28a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "43553138671068495841916643857804982519",
            "length":  579
        },
        "id":  "CVE-2026-8336-573b1c19",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp",
            "function":  "MeasurementMap::insertOne"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "284460113755408055723012211659961360780",
            "length":  599
        },
        "id":  "CVE-2026-8336-7b34e191",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp",
            "function":  "MeasurementMap::insertOne"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "65317806234226920521720845331578521082",
                "245205739251347437876425597495755876481",
                "109749818435937265218130737097210075244",
                "247724741587646782412887786320692163933",
                "328299337808136919563643867456051799671",
                "168020673177810988486900283615589649830",
                "170052273858241919648121125823866015059",
                "177147919177640274616929074969145590120",
                "140861398997613641900615087528359816369",
                "294172095836668649572112064188327133592",
                "103431700251158212873865689548307615353",
                "21787099695343064233815986318428483963",
                "157562864901160561707888628653518219141",
                "250504151046058816035709411326397744704"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-a00600ff",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "220012559814535802246991203699235448665",
                "292813745953450357917782590991431684195",
                "151782744504930929400284312418396007787"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-ac57b75a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "291363120804310266702293571491914596809",
                "33869876076183871238703932409763090783"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-ae8682c1",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "17181056965332531028681155129851284942",
            "length":  988
        },
        "id":  "CVE-2026-8336-b20f3e14",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp",
            "function":  "Obj::search"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "113590516626605239294940485100571288810",
                "200762295114800290845951546202029883764",
                "268316385711008539282353089121521072588",
                "184940241524942480541267925278565633866",
                "57908861127480025164680135191487105877",
                "22008568524960951903435505329165604572",
                "283531283680862789255620472702442978052"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-b7e9811b",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "189988079331693010828710016868224288344",
                "156644622417418443415807260198870532652",
                "127287703221177560262489158943077347278",
                "238171269685132529499568082580439161603",
                "5099464907976194915440695461937409677",
                "12579336589641520520804530894688239105",
                "9615073687642051710079005079633121505",
                "128352877459597030677197941825486183445",
                "73863290553960507209707682947063567550",
                "191257911512827898256694559820641371502",
                "127277178768055444847121840322197792737"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-8336-ca202f9e",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "221304163357851772164061278326293544638",
            "length":  1066
        },
        "id":  "CVE-2026-8336-dd5b676f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d",
        "target":  {
            "file":  "src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp",
            "function":  "Obj::insert"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:09:25Z"