Search CVE reports


Toggle filters

21 – 30 of 1935 results


CVE-2026-13074

Medium priority
Needs evaluation

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13073

Medium priority
Needs evaluation

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13072

Medium priority
Needs evaluation

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13071

Medium priority
Needs evaluation

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13070

Medium priority
Needs evaluation

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13069

Medium priority
Needs evaluation

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13068

Medium priority
Needs evaluation

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13067

Medium priority
Needs evaluation

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13066

Medium priority
Needs evaluation

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-13065

Medium priority
Needs evaluation

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in...

1 affected package

mongodb

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages