CVE-2026-13064
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 8.0 < 8.0.28 | affected |
| MongoDB | MongoDB Server | 8.2.0 < 8.2.12 | affected |
| MongoDB | MongoDB Server | 8.3.0 < 8.3.7 | affected |
Weaknesses
- CWE-407: CWE-407: Inefficient Algorithmic Complexity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.