Skip to content
MongoDBCVE-2026-13076

MongoDB Server: resource exhaustion

High7.1CVE-2026-13076 · Published Jul 22, 2026 · updated Aug 18, 2026

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.

MongoDB advisory

Affected versions

PackageAffectedFixed in
MongoDB Server
Product
>= 8.3.0, < 8.3.78.3.7
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More MongoDB advisories

All MongoDB
Advisory
MongoDB Server: reachable assertion
High7.1Jul 22
MongoDB Compass: command injection
High8.4Jul 22
MongoDB Server: resource exhaustion
Medium6.9Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: out-of-bounds read
High7.1Jul 22
MongoDB Server: missing authorization
Medium6.3Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.