CVE-2026-4147
Received
Received - Intake
Uninitialized Stack Memory Disclosure via MongoDB filemd5 Command
Publication date: 2026-03-17
Last updated on: 2026-04-10
Assigner: MongoDB, Inc.
Description
Description
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mongodb | mongodb | 8.3.0 |
| mongodb | mongodb | From 7.0.0 (inc) to 7.0.31 (exc) |
| mongodb | mongodb | From 8.0.0 (inc) to 8.0.20 (exc) |
| mongodb | mongodb | From 8.2.0 (inc) to 8.2.6 (exc) |
| mongodb | mongodb | 8.3.0 |
| mongodb | mongodb | 8.3.0 |
| mongodb | mongodb | 8.3.0 |
| mongodb | mongodb | 8.3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-908 | The product uses or accesses a resource that has not been initialized. |
| CWE-457 | The code uses a variable that has not been initialized, leading to unpredictable or unintended results. |