Common Vulnerabilities and Exposures (CVE)

CVE-2026-13070

Jul 23, 2026 14:21:38 UTC

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connectio...

CVE-2026-13071

Jul 23, 2026 14:21:17 UTC

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.

CVE-2026-57428

Jul 23, 2026 14:21:10 UTC

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

CVE-2026-13072

Jul 23, 2026 14:20:54 UTC

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or othe...

CVE-2026-47003

Jul 23, 2026 14:20:43 UTC

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated...

CVE-2026-47425

Jul 23, 2026 14:20:36 UTC

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto ...

CVE-2026-13073

Jul 23, 2026 14:20:26 UTC

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issu...

CVE-2026-13074

Jul 23, 2026 14:20:01 UTC

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a ...

CVE-2026-57373

Jul 23, 2026 14:19:54 UTC

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

CVE-2026-12548

Jul 23, 2026 14:19:47 UTC

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap bu...

CVE-2026-13075

Jul 23, 2026 14:19:39 UTC

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and requires...

CVE-2026-13077

Jul 23, 2026 14:19:15 UTC

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malform...

CVE-2026-27403

Jul 23, 2026 14:18:56 UTC

Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.

CVE-2026-13078

Jul 23, 2026 14:18:44 UTC

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod p...

CVE-2026-13060

Jul 23, 2026 14:18:21 UTC

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and dur...