Security Advisory

CVE-2026-13066

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-22 19:17:08
Last updated 2026-07-23 14:23:10
Assigner mongodb
CVSS score 7.1
State PUBLISHED

Description

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.