CyberRota Analysis
AI-GeneratedMongoDB servers are vulnerable to a denial-of-service attack due to an unauthenticated remote client being able to exploit the awaitable hello command in exhaust mode, leading to excessive CPU consumption. This vulnerability allows attackers to create a response loop that bypasses standard throttling mechanisms, potentially degrading server availability. Organizations using MongoDB should prioritize addressing this issue to mitigate the risk of service disruption.
Original NVD Description
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.
Related CVEs
Other vulnerabilities affecting the same vendor(s)