Security Advisory

CVE-2026-13063

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-22 19:18:26
Last updated 2026-07-23 19:09:15
Assigner mongodb
CVSS score 5.3
State PUBLISHED

Description

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.