CVE-2026-13064

Summary

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls.

Affected Software

VendorProductVersion RangeStatus
MongoDBMongoDB Server8.0 < 8.0.28affected
MongoDBMongoDB Server8.2.0 < 8.2.12affected
MongoDBMongoDB Server8.3.0 < 8.3.7affected

Weaknesses

  • CWE-407: CWE-407: Inefficient Algorithmic Complexity

References