---
cve: "CVE-2026-1848"
severity: "HIGH"
cvss: 8.2
epss: "26%"
vendor: "MongoDB Inc"
kev: false
exploited: false
published: "2026-02-10 19:15:51"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T03:43:20+02:00"
---

# CVE-2026-1848

> 8.2 HIGH

## Beschreibung

Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- b409fb494004bf0f7284059b806b3b751a2ec5d9 (Commit)
- af851bae82a9fc9d93657f9707a845990460898e (Commit)

## Referenzen

- <https://jira.mongodb.org/browse/SERVER-114695>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-1848) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
