GHSA-p5gh-5wmf-x9p2HighCVSS 6.5

The $regexFindAll expression can be used by an authenticated user who can run aggregation...

Published
September 8, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.

🔗 References (4)