Back to CVE List

CVE-2026-13065

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-476
Source
NVD
Vendor
MongoDB
Product
MongoDB Server

External References

Discussion (0)

Add Comment

No comments yet. Be the first!