Reachable assertion in MongoDB Server - CVE-2026-13073
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to reachable assertion in aggregation command processing when handling a crafted aggregation command with a specific combination of aggregation options. A remote user can send a crafted aggregation command to cause a denial of service.
The mongod process terminates abnormally, affecting all connected clients until the process is restarted.