Use-after-free in MongoDB Server - CVE-2026-13071
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in server-side JavaScript aggregation expressions when processing aggregation expressions that execute server-side JavaScript during document processing. A remote user can send specially crafted aggregation expressions to cause a denial of service.
The issue can terminate the mongod process and requires read access.