CVE-2026-13071
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 7.0 < 7.0.39 | affected |
| MongoDB | MongoDB Server | 8.0 < 8.0.28 | affected |
| MongoDB | MongoDB Server | 8.2.0 < 8.2.12 | affected |
| MongoDB | MongoDB Server | 8.3.0 < 8.3.7 | affected |
Weaknesses
- CWE-416: CWE-416: Use After Faree
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.