Description
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whether it begins with an Atlas Search stage. For $rankFusion and $scoreFusion, this inspection reads the first element on each stage’s input pipeline array without first verifying that the array is non-empty. Supplying an empty pipeline causes a null pointer dereference and crashes the server. This issue affects MongoDB Server 8.2 versions prior to 8.2.7.
Remediation
References
Related Vulnerabilities
SharePoint Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-24955)
Angular : Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-88056)
YetiForce CRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-1411)
WordPress Plugin PDW Media File Browser 'upload.php' Arbitrary File Upload (1.1)
WordPress Deserialization of Untrusted Data Vulnerability (CVE-2022-21663)