CVE-2026-13063
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Summary
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 8.2.0 < 8.2.12 | affected |
| MongoDB | MongoDB Server | 8.3.0 < 8.3.7 | affected |
Weaknesses
- CWE-190: CWE-190: Integer Overflow or Wraparound
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.