CRITICAL🇵🇱 Wersja polska

CVE-2026-13072

CVSS 9.2v4.0pub. 2026-07-22upd. 2026-08-18

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mongodb

    APP
    Mongodb
    7.0.0 – 7.0.39 (excl.)8.0.0 – 8.0.28 (excl.)8.2.0 – 8.2.12 (excl.)8.3.0 – 8.3.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-15535CRITICAL9.1PL ✓same product

MongoDB: podatność w kompresji protokołu sieciowego — DoS i modyfikacja pamięci

CVE-2025-14847HIGH8.7⚠ KEVsame product

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by ...

CVE-2026-13055HIGH7.1PL ✓same product

MongoDB: DoS poprzez wyrażenie agregacji $_internalIndexKey z compound wildcard index

CVE-2026-13056HIGH7.1PL ✓same product

MongoDB – wyczerpanie pamięci przez wyrażenia generujące duże tablice (DoS)

CVE-2026-13058HIGH7.1PL ✓same product

MongoDB: DoS przez nieprawidłowe polecenie transakcji — CWE-617