CVE-2026-13056
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.40%
- CWE
- CWE-1325
- Published
- 2026-07-22
- Last modified
- 2026-07-24
Affected products
- MongoDB MongoDB Server
- MongoDB MongoDB Server
Weakness type
Related vulnerabilities
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark