← Back to CVE search

CVE-2026-13065

MongoDB

Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

CVSS 6.5EPSS 0.297%Risk 0.67
View source
Published
2026-07-22 20:16:44
Affected versions
unknown
Type
Critical software
Last modified
2026-08-05 14:45:00
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H