CVE-2026-13056
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 8.0 < 8.0.28 | affected |
| MongoDB | MongoDB Server | 8.3.0 < 8.3.7 | affected |
Weaknesses
- CWE-1325: CWE-1325: Improperly Controlled Sequential Memory Allocation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.