MongoDb Use After Free Vulnerability - CVE-2026-8336
After invoking _internalJsEmit which is not intended to be directly accessible or mapreduce commands map function in a certain way an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through where function mapreduce reduce stage etc.) is used also in a specific way resulting in a post-authentication denial-of-service. This issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.