CVE-2026-13065

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-127280 Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-07-22 20:16

Updated : 2026-08-05 14:45


NVD link : CVE-2026-13065

Mitre link : CVE-2026-13065

CVE.ORG link : CVE-2026-13065


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-476

NULL Pointer Dereference