CVE-2026-1848Disclosure(mongodb / mongodb)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mongodb

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mongodb

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-10: 2Mentions · 2026-02-16: 1Technical Details · 2026-02-10: 102-1002-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-102
Disclosure1General1
2026-02-161
Disclosure1
Full discourse3 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos MongoDB ❗ CVE-2026-25611 ❗ CVE-2026-1848 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mongodb/ https://t.co/VjiO5cn3qZ

    Post summary

    The CERT notice announces two new MongoDB vulnerabilities (CVE‑2026‑25611 and CVE‑2026‑1848) without providing further technical details or exploitation information.

    00001115
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1848 Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds availa… https://www.cve.org/CVERecord?id=CVE-2026-1848

    Post summary

    The text references CVE-2026-1848, describing a denial‑of‑service issue where proxy connections are not counted, potentially leading to server crashes; no PoC, exploit, patch, or active exploitation is mentioned.

    0001081
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1848 Proxy Protocol Header Handling Vulnerability Leading to Server Res... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1848 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely lists CVE‑2026‑1848 with a link to a vulnerability details page, without providing any concrete technical information or actionable intelligence.

    0000058
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmongodbmongodb---

Explore more