← Vulnerability feed

Vulnerability record · CVE-2013-1892 · published 1 October 2013

CVE-2013-1892: Mongodb improper input validation vulnerability

Mongodb · Mongodb

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

6.0 CVSS 2.0 Medium EPSS 45% · top 1.3% CWE-20 · Improper input validation
6.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1892 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-14847MongoDB Server heap memory disclosure via compressed protocol headersMismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Ser…KEVEPSS 83%analysed9.8CVE-2025-3085Mongodb vulnerabilityA MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…EPSS 0.27%9.8CVE-2024-8654Mongodb use of uninitialized resource vulnerabilityMongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…EPSS 0.37%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.8CVE-2012-3460Redhat enterprise mrg improper input validation vulnerabilitycumin: At installation postgresql database user created without passwordEPSS 1.3%9.2CVE-2026-82067Mongodb vulnerabilityImproper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in …EPSS 0.51%9.2CVE-2026-13072Mongodb heap-based buffer overflow vulnerabilityWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…EPSS 0.40%9.1CVE-2017-15535Mongodb vulnerabilityMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2013-1892), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.