CVE-2021-32040 describes a stack overflow vulnerability in MongoDB Server versions 4.2, 4.4, and 5.0, caused by excessively long aggregation pipelines with specific stages. This flaw allows an unauthenticated attacker to remotely trigger a Denial of Service (DoS) by crashing the MongoDB instance. Rated 7.5 HIGH on CVSS, the attack requires low complexity and no user interaction, but only impacts availability. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.2.16CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.11CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.4CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.