Skip to content
MongoDBCVE-2026-13065

MongoDB Server: denial of service

High7.1CVE-2026-13065 · Published Jul 22, 2026 · updated Aug 5, 2026

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

MongoDB advisory

Affected versions

PackageAffectedFixed in
MongoDB Server
Product
>= 7.0, < 7.0.397.0.39
>= 8.0, < 8.0.288.0.28
>= 8.2.0, < 8.2.128.2.12
>= 8.3.0, < 8.3.78.3.7
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-476

More MongoDB advisories

All MongoDB
Advisory
MongoDB Server: reachable assertion
High7.1Jul 22
MongoDB Compass: command injection
High8.4Jul 22
MongoDB Server: resource exhaustion
Medium6.9Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: out-of-bounds read
High7.1Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.