Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f98-54v9-5hh9

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

EPSS

Процентиль: 22%
0.00297
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

CVSS3: 6.5
nvd
около 1 месяца назад

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

CVSS3: 6.5
debian
около 1 месяца назад

A user with read-only privileges is able to craft an aggregation pipel ...

EPSS

Процентиль: 22%
0.00297
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-476