Loading HuntDB...

GHSA-hmq6-2xj3-79w5

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB versions prior to 5.0.4, 4.4.11, 4.2.16.

Related CVEs

Key Information

GHSA ID
GHSA-hmq6-2xj3-79w5
Published
April 13, 2022 12:00 AM
Last Modified
February 23, 2024 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.