Back to CVE List

CVE-2026-13055

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-617
Source
NVD
Vendor
MongoDB
Product
MongoDB Server

External References

Discussion (0)

Add Comment

No comments yet. Be the first!