CyberRota Analysis
AI-GeneratedAuthenticated users with access to run aggregation pipeline stages in MongoDB are vulnerable to a flaw in the $regexFindAll expression, which can lead to server crashes under specific conditions. This vulnerability occurs when the regex match initiates in the middle of a multi-code-unit character, causing an assertion failure during query execution. Organizations using MongoDB should prioritize addressing this issue to prevent potential service disruptions.
Original NVD Description
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions theĀ regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Related CVEs
Other vulnerabilities affecting the same vendor(s)