Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-13071 — Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Term…

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory ha…

mongodb | Remote | Information Disclosure
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
6.0 MEDIUM
CVE-2026-13070 — Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Ter…

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enab…

mongodb | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13069 — Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhau…

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used t…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
4.2 MEDIUM
CVE-2026-13068 — MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database…

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for ot…

mongodb | Remote | Authorization
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-13067 — tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unin…

mongodb | Authentication
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-13066 — Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the clien…

mongodb | Remote | Information Disclosure
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13065 — MongoDB $linearFill Window Function Improper Input Validation Leading to Process Terminat…

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminat…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13064 — MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The r…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-13063 — libmongocrypt Improper Input Validation Leading to Process Termination

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13062 — MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Comman…

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sendin…

mongodb | Remote | Misconfiguration
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-13061 — Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions …

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cl…

mongodb | Remote | Authorization
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13060 — $graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Co…

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage …

mongodb | Remote | Authorization
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
8.6 HIGH
CVE-2026-13059 — Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Cont…

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain c…

mongodb | Remote | Authorization
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-13058 — Transaction Command Insufficient Input Validation Leading to Process Termination

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue st…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
6.0 MEDIUM
CVE-2026-13057 — Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Colle…

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use interna…

mongodb | Remote | Authorization
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to cons…

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-13055 — Server crash via aggregation pipeline expression with compound wildcard index specificati…

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, trigge…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-3482 — IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive i…

Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-22049 — NetApp ONTAP WebAuthn Authentication Bypass Vulnerability

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could …

ontap_9 | Remote | Authentication
Jul 22, 2026 Jul 25, 2026
Jul 22, 2026
Jul 25, 2026
0.0 NA
CVE-2026-16624 — CVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including …

| Authorization
Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
Showing 20 of 8954 Results