CVE-2026-13063
EUVD-2026-4779822.07.2026, 20:16
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 8.2.0 ≤ 𝑥 < 8.2.12 | CNA |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.7 | CNA |