Allocation of Resources Without Limits or Throttling in MongoDB Server - CVE-2026-13074
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the awaitable hello command in exhaust mode when handling a specific combination of parameters. A remote attacker can send crafted command parameters to cause a denial of service.
A small number of connections can degrade server availability by triggering excessive CPU consumption.