CVE-2026-13064
- EPSS 0.23%
- Veröffentlicht 22.07.2026 19:17:54
- Zuletzt bearbeitet 05.08.2026 14:46:19
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted ...
CVE-2026-13065
- EPSS 0.3%
- Veröffentlicht 22.07.2026 19:17:29
- Zuletzt bearbeitet 05.08.2026 14:45:00
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The i...
CVE-2026-13066
- EPSS 0.23%
- Veröffentlicht 22.07.2026 19:17:08
- Zuletzt bearbeitet 05.08.2026 14:43:56
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information discl...
CVE-2026-13067
- EPSS 0.1%
- Veröffentlicht 22.07.2026 19:16:38
- Zuletzt bearbeitet 05.08.2026 14:41:50
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 auth...
CVE-2026-13068
- EPSS 0.15%
- Veröffentlicht 22.07.2026 19:16:13
- Zuletzt bearbeitet 05.08.2026 14:12:58
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization...
CVE-2026-13069
- EPSS 0.17%
- Veröffentlicht 22.07.2026 19:15:38
- Zuletzt bearbeitet 05.08.2026 13:23:01
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulti...
- EPSS 0.13%
- Veröffentlicht 22.07.2026 19:15:15
- Zuletzt bearbeitet 05.08.2026 13:21:33
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affect...
CVE-2026-13071
- EPSS 0.25%
- Veröffentlicht 22.07.2026 19:14:51
- Zuletzt bearbeitet 18.08.2026 16:18:13
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.
CVE-2026-13072
- EPSS 0.4%
- Veröffentlicht 22.07.2026 19:14:15
- Zuletzt bearbeitet 18.08.2026 16:16:58
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintend...
CVE-2026-13073
- EPSS 0.22%
- Veröffentlicht 22.07.2026 19:13:55
- Zuletzt bearbeitet 18.08.2026 16:16:09
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems fr...