Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-82055

CVE-2026-82055: MongoDB 2dsphere Index DOS Vulnerability

CVE-2026-82055 is a denial of service vulnerability in MongoDB's 2dsphere index that causes server crashes through null pointer dereference. This post explains the technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-82055 Overview

CVE-2026-82055 is a null pointer dereference vulnerability [CWE-476] in MongoDB's 2dsphere index key generation logic. A specially crafted GeoJSON document inserted into a collection with a 2dsphere index triggers an inconsistency in geometry parsing. The parser leaves an internal object in a partially initialized state, and later access during index key generation dereferences a null pointer. The condition terminates the mongod process, producing a denial of service.

Exploitation requires an authenticated account with write access to a collection carrying a 2dsphere index. No user interaction is needed beyond the malicious document insert.

Critical Impact

An authenticated user with write privileges can crash the mongod process by inserting a crafted GeoJSON document into any collection containing a 2dsphere index.

Affected Products

  • MongoDB Server (mongod) — see MongoDB Issue SERVER-130202 for affected versions
  • Deployments using 2dsphere geospatial indexes
  • Any MongoDB collection accepting GeoJSON writes from authenticated users

Discovery Timeline

  • 2026-09-08 - CVE-2026-82055 published to NVD
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-82055

Vulnerability Analysis

MongoDB's 2dsphere index supports geospatial queries over GeoJSON geometries. When a document is inserted, the server parses the geometry to derive index keys covering the corresponding S2 cells. The vulnerability arises when a malformed or edge-case GeoJSON payload causes the geometry parser to return without fully initializing an internal geometry object. Subsequent index key generation assumes the object is valid and dereferences an internal pointer that was never set.

The result is an immediate crash of the mongod process. In replica set or sharded deployments, repeated exploitation can force failover loops and impact availability across the cluster. Because the vulnerability trips during the write path, the malicious document may be replayed from the oplog, potentially crashing secondary nodes as well.

Root Cause

The root cause is inconsistent error handling between the GeoJSON geometry parser and the downstream index key generator. The parser accepts a document as syntactically valid GeoJSON but fails partway through geometry construction. This leaves the internal object partially initialized without signaling the failure upstream. The index key generation code then treats the object as complete and dereferences a null member pointer.

Attack Vector

The attack requires network access to the MongoDB instance and authenticated credentials with write permission on a collection that carries a 2dsphere index. The attacker submits a specially crafted GeoJSON document through a standard insert or update operation. No shell access, elevated role, or cryptographic bypass is required. The vulnerability manifests during normal write processing, so any application path that forwards user-controlled geospatial data to MongoDB is a potential trigger. Full technical detail is tracked in the vendor issue MongoDB SERVER-130202.

Detection Methods for CVE-2026-82055

Indicators of Compromise

  • Unexpected mongod process termination correlated with a recent insert or update operation on a collection with a 2dsphere index
  • Crash dumps or stack trace entries in MongoDB logs referencing geometry parsing or S2 index key generation
  • Replica set secondaries crashing shortly after applying a specific oplog entry containing a GeoJSON document

Detection Strategies

  • Alert on mongod process exits with non-zero status codes on database hosts
  • Correlate MongoDB FATAL log entries with recent write operations against collections holding 2dsphere indexes
  • Monitor for authenticated users generating repeated write failures immediately followed by connection resets

Monitoring Recommendations

  • Ingest MongoDB audit and diagnostic logs into a centralized analytics platform for cross-node correlation
  • Track write operations touching GeoJSON fields and flag anomalous document structures
  • Baseline replica set health metrics such as state transitions and unexpected elections to catch cascading crashes

How to Mitigate CVE-2026-82055

Immediate Actions Required

  • Upgrade mongod to the fixed release identified in MongoDB SERVER-130202 once available
  • Audit database roles and remove write permissions from accounts that do not require them
  • Restrict application-layer inputs so that untrusted GeoJSON payloads are validated before insert

Patch Information

Refer to MongoDB Issue SERVER-130202 for the authoritative list of affected and patched MongoDB Server versions. Apply the vendor patch to all replica set members and shards, prioritizing internet-facing clusters and multi-tenant environments where write access is broadly delegated.

Workarounds

  • Enforce strict GeoJSON schema validation at the application tier before writes reach MongoDB
  • Use MongoDB $jsonSchema collection validators to reject documents with malformed geometry fields
  • Temporarily drop non-essential 2dsphere indexes on collections that accept untrusted writes until the patch is applied
  • Limit write access on impacted collections to a minimal set of trusted service accounts
bash
# Example collection validator rejecting non-conforming GeoJSON geometry types
db.runCommand({
  collMod: "places",
  validator: {
    $jsonSchema: {
      bsonType: "object",
      properties: {
        location: {
          bsonType: "object",
          required: ["type", "coordinates"],
          properties: {
            type: { enum: ["Point", "Polygon", "LineString"] },
            coordinates: { bsonType: "array" }
          }
        }
      }
    }
  },
  validationLevel: "strict",
  validationAction: "error"
})

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.