← Vulnerability feed

Vulnerability record · CVE-2026-13056 · published 22 July 2026

CVE-2026-13056: Mongodb vulnerability

Mongodb · Mongodb

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

7.1 CVSS 4.0 High EPSS 0.40% · top 68.1% CWE-1325 · CWE-1325
7.1CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
5 Aug 2026Last modified by NVD

Description

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jira.mongodb.org/browse/SERVER-124355 Vendor AdvisoryIssue Tracking

Track CVE-2026-13056 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-14847MongoDB Server heap memory disclosure via compressed protocol headersMismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Ser…KEVEPSS 83%analysed9.8CVE-2025-3085Mongodb vulnerabilityA MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…EPSS 0.27%9.8CVE-2024-8654Mongodb use of uninitialized resource vulnerabilityMongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…EPSS 0.37%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.2CVE-2026-82067Mongodb vulnerabilityImproper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in …EPSS 0.51%9.2CVE-2026-13072Mongodb heap-based buffer overflow vulnerabilityWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…EPSS 0.40%9.1CVE-2017-15535Mongodb vulnerabilityMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…EPSS 1.6%9.0CVE-2026-18691Mongodb vulnerabilityAn issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2026-13056), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.