It may be possible to have an extremely long aggregation...
High severity
Unreviewed
Published
Apr 13, 2022
to the GitHub Advisory Database
•
Updated Mar 3, 2024
Description
Published by the National Vulnerability Database
Apr 12, 2022
Published to the GitHub Advisory Database
Apr 13, 2022
Last updated
Mar 3, 2024
It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB versions prior to 5.0.4, 4.4.11, 4.2.16.
References