CVE-2026-13063
CVE-2026-13063 is a medium-severity vulnerability in Mongodb with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-190.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (14th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-190
- Affected product: Mongodb
- Published:
- Last modified:
Description
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.
Frequently asked questions
- What is CVE-2026-13063?
- An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.
- How severe is CVE-2026-13063?
- CVE-2026-13063 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-13063 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-13063?
- CVE-2026-13063 affects Mongodb. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-13063?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-13063 published?
- CVE-2026-13063 was published on 2026-07-22 and last updated on 2026-08-05.
References
Affected products (1)
- cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
More vulnerabilities in Mongodb
- CVE-2017-15535 — Critical (CVSS 9.1): MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting,…
- CVE-2026-11933 — High (CVSS 8.8): A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents…
- CVE-2026-8053 — High (CVSS 8.8): An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write…
- CVE-2026-4148 — High (CVSS 8.8): A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who…
- CVE-2024-1351 — High (CVSS 8.8): Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which…
- CVE-2025-0755 — High (CVSS 8.4): The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when…
Other CWE-190 (Integer Overflow or Wraparound) vulnerabilities
- CVE-2026-4689 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was…
- CVE-2026-24814 — Critical (CVSS 10.0): Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is…
- CVE-2025-64721 — Critical (CVSS 10.0): Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions…
- CVE-2015-5108 — Critical (CVSS 10.0): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC…
- CVE-2015-5097 — Critical (CVSS 10.0): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC…
- CVE-2013-2555 — Critical (CVSS 10.0): Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before…
Browse all CWE-190 (Integer Overflow or Wraparound) vulnerabilities →