<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:13:30.904593+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mongodb-2026-82056</id>
    <title>BIT-mongodb-2026-82056 — Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of Service</title>
    <updated>2026-10-03T06:13:30.984197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mongodb</p>
<p>A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mongodb-2026-82056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1157</id>
    <title>certfr-2026-avi-1157 — De multiples vulnérabilités ont été découvertes dans MongoDB Server. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T06:13:30.984293+00:00</updated>
    <content>certfr-2026-avi-1157</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365277</id>
    <title>EUVD-2026-365277</title>
    <updated>2026-10-03T06:13:30.984335+00:00</updated>
    <content>EUVD-2026-365277</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82056</id>
    <title>fkie_cve-2026-82056</title>
    <updated>2026-10-03T06:13:30.984366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-82056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-63w5-8wj5-r44q</id>
    <title>GHSA-63w5-8wj5-r44q</title>
    <updated>2026-10-03T06:13:30.984420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-63w5-8wj5-r44q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82056</id>
    <title>UBUNTU-CVE-2026-82056</title>
    <updated>2026-10-03T06:13:30.984465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: mongodb, Ubuntu:Pro:16.04:LTS: mongodb, Ubuntu:Pro:18.04:LTS: mongodb, Ubuntu:Pro:20.04:LTS: mongodb</p>
<p>A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying structures have been freed, leading to a server crash. An authenticated user with readWrite privileges can trigger this condition through specific concurrent text-search and index management operations, resulting in denial of service for all connected clients. This</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3236</id>
    <title>WID-SEC-W-2026-3236 — MongoDB Server: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:13:30.984519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MongoDB Server ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen und beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3236"/>
  </entry>
</feed>
