Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-118849 |
|
Thu, 02 Apr 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb mongodb
|
|
| CPEs | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Mongodb mongodb
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb Server |
|
| Vendors & Products |
Mongodb
Mongodb mongodb Server |
Tue, 17 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk. | |
| Title | Memory safety issues in slot-based execution hash table spill | |
| Weaknesses | CWE-415 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-03-17T20:08:24.920Z
Reserved: 2026-03-17T18:55:18.644Z
Link: CVE-2026-4358
Updated: 2026-03-17T20:06:48.279Z
Status : Analyzed
Published: 2026-03-17T20:16:15.030
Modified: 2026-04-02T12:16:02.273
Link: CVE-2026-4358
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:23:36Z