Allocation of Resources Without Limits or Throttling in MongoDB Server - CVE-2026-13075
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the server error-handling path for the $rankFusion and $scoreFusion aggregation stages when generating error suggestions during aggregation query processing. A remote user can send crafted aggregation queries to cause a denial of service.
Exploitation requires the ability to run aggregation queries, and the mongod process may be terminated by the operating system under memory pressure.