Security Advisory

CVE-2026-13065

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-22 19:17:29
Last updated 2026-07-23 15:02:01
Assigner mongodb
CVSS score 7.1
State PUBLISHED

Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.