Allocation of Resources Without Limits or Throttling in MongoDB Server - CVE-2026-13075

 

Allocation of Resources Without Limits or Throttling in MongoDB Server - CVE-2026-13075

Published: August 18, 2026


Vulnerability identifier: #VU144108
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13075
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the server error-handling path for the $rankFusion and $scoreFusion aggregation stages when generating error suggestions during aggregation query processing. A remote user can send crafted aggregation queries to cause a denial of service.

Exploitation requires the ability to run aggregation queries, and the mongod process may be terminated by the operating system under memory pressure.


Affected software

MongoDB Server

How to mitigate CVE-2026-13075

Install security update from vendor's website.

MongoDB Server - addressed in versions 8.2.12, 8.3.7

External References

Related Security Bulletins