Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13074

Опубликовано: 22 июл. 2026
Источник: debian
EPSS Низкий

Описание

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongodbremovedpackage

Примечания

  • https://jira.mongodb.org/browse/SERVER-128517

EPSS

Процентиль: 18%
0.0026
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.

CVSS3: 5.3
nvd
около 1 месяца назад

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.

CVSS3: 5.3
github
около 1 месяца назад

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.

EPSS

Процентиль: 18%
0.0026
Низкий