{"id":"CVE-2026-8336","summary":"Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands","details":"After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.\n\nThis issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.","aliases":["BIT-mongodb-2026-8336"],"modified":"2026-08-12T16:09:25.917789Z","published":"2026-05-13T00:16:16.568Z","database_specific":{"cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8336.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.2"},{"fixed":"8.2.9"},{"introduced":"8.3"},{"fixed":"8.3.2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"mongodb"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8336.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8336"},{"type":"REPORT","url":"https://jira.mongodb.org/browse/SERVER-121610"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo","events":[{"introduced":"b993867dce63dd366cd93e60f3f425ed716f6497"},{"fixed":"551096db8ad4a951af553de51c5485d5fd91d40d"},{"introduced":"0f29b043a58fdd251ce0a0b32754b8459613c933"},{"fixed":"c531abff36f228c5ff24735ddf31a23536716ab0"}],"database_specific":{"cpe":"cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.2.0"},{"fixed":"8.2.9"},{"introduced":"8.3.0"},{"fixed":"8.3.2"}],"source":"CPE_RANGE"}}],"versions":["r8.3.0","r8.3.1","r8.2.4-alpha1","r8.2.4-alpha0","r8.2.3-alpha0","r8.2.2-rc0","r8.2.2","r8.2.1-rc1","r8.2.1","r8.2.1-rc0","r8.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8336.json","vanir_signatures_modified":"2026-08-12T16:09:25Z","vanir_signatures":[{"id":"CVE-2026-8336-08ad15c4","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp","function":"Obj::search"},"deprecated":false,"digest":{"length":988,"function_hash":"17181056965332531028681155129851284942"}},{"source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"},"deprecated":false,"digest":{"line_hashes":["65317806234226920521720845331578521082","245205739251347437876425597495755876481","109749818435937265218130737097210075244","247724741587646782412887786320692163933","328299337808136919563643867456051799671","168020673177810988486900283615589649830","170052273858241919648121125823866015059","177147919177640274616929074969145590120","140861398997613641900615087528359816369","294172095836668649572112064188327133592","103431700251158212873865689548307615353","21787099695343064233815986318428483963","157562864901160561707888628653518219141","250504151046058816035709411326397744704"],"threshold":0.9},"id":"CVE-2026-8336-3797dc56","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["292572099948037041716578539154433823516","168860491958264251483141325059901754282","304117868208266248508117415656816929694","179593579132299061605021834936400112936"],"threshold":0.9},"id":"CVE-2026-8336-3d904649","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"}},{"id":"CVE-2026-8336-46a07206","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp","function":"Obj::insert"},"deprecated":false,"digest":{"function_hash":"70226459102367042737321538611145560590","length":1050}},{"id":"CVE-2026-8336-55c6a28a","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"},"deprecated":false,"digest":{"line_hashes":["291363120804310266702293571491914596809","33869876076183871238703932409763090783"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp","function":"MeasurementMap::insertOne"},"deprecated":false,"digest":{"function_hash":"43553138671068495841916643857804982519","length":579},"id":"CVE-2026-8336-573b1c19"},{"deprecated":false,"digest":{"function_hash":"284460113755408055723012211659961360780","length":599},"id":"CVE-2026-8336-7b34e191","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp","function":"MeasurementMap::insertOne"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d","target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp"},"deprecated":false,"digest":{"line_hashes":["65317806234226920521720845331578521082","245205739251347437876425597495755876481","109749818435937265218130737097210075244","247724741587646782412887786320692163933","328299337808136919563643867456051799671","168020673177810988486900283615589649830","170052273858241919648121125823866015059","177147919177640274616929074969145590120","140861398997613641900615087528359816369","294172095836668649572112064188327133592","103431700251158212873865689548307615353","21787099695343064233815986318428483963","157562864901160561707888628653518219141","250504151046058816035709411326397744704"],"threshold":0.9},"id":"CVE-2026-8336-a00600ff"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["220012559814535802246991203699235448665","292813745953450357917782590991431684195","151782744504930929400284312418396007787"]},"id":"CVE-2026-8336-ac57b75a","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"}},{"target":{"file":"src/mongo/db/timeseries/bucket_catalog/minmax_test.cpp"},"deprecated":false,"digest":{"line_hashes":["291363120804310266702293571491914596809","33869876076183871238703932409763090783"],"threshold":0.9},"id":"CVE-2026-8336-ae8682c1","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"},{"deprecated":false,"digest":{"function_hash":"17181056965332531028681155129851284942","length":988},"id":"CVE-2026-8336-b20f3e14","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d","target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp","function":"Obj::search"}},{"signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map_test.cpp"},"deprecated":false,"digest":{"line_hashes":["113590516626605239294940485100571288810","200762295114800290845951546202029883764","268316385711008539282353089121521072588","184940241524942480541267925278565633866","57908861127480025164680135191487105877","22008568524960951903435505329165604572","283531283680862789255620472702442978052"],"threshold":0.9},"id":"CVE-2026-8336-b7e9811b","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["189988079331693010828710016868224288344","156644622417418443415807260198870532652","127287703221177560262489158943077347278","238171269685132529499568082580439161603","5099464907976194915440695461937409677","12579336589641520520804530894688239105","9615073687642051710079005079633121505","128352877459597030677197941825486183445","73863290553960507209707682947063567550","191257911512827898256694559820641371502","127277178768055444847121840322197792737"],"threshold":0.9},"id":"CVE-2026-8336-ca202f9e","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/c531abff36f228c5ff24735ddf31a23536716ab0","target":{"file":"src/mongo/db/timeseries/bucket_catalog/measurement_map.cpp"}},{"target":{"file":"src/mongo/db/timeseries/bucket_catalog/flat_bson.cpp","function":"Obj::insert"},"deprecated":false,"digest":{"length":1066,"function_hash":"221304163357851772164061278326293544638"},"id":"CVE-2026-8336-dd5b676f","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/551096db8ad4a951af553de51c5485d5fd91d40d"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:M/U:Red"}]}