Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13076

Опубликовано: 22 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.7 (исключая)

EPSS

Процентиль: 35%
0.0042
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

CVSS3: 6.5
debian
около 1 месяца назад

An authenticated user can cause a {{mongod}} process to be terminated ...

CVSS3: 6.5
github
около 1 месяца назад

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

EPSS

Процентиль: 35%
0.0042
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770