CVE-2026-13066
EUVD-2026-4779522.07.2026, 20:16
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mongodb | mongodb | 7.0 ≤ 𝑥 < 7.0.39 | CNA |
| mongodb | mongodb | 8.0 ≤ 𝑥 < 8.0.28 | CNA |
| mongodb | mongodb | 8.2.0 ≤ 𝑥 < 8.2.12 | CNA |
| mongodb | mongodb | 8.3.0 ≤ 𝑥 < 8.3.7 | CNA |