Resource Exhaustion Vulnerability in MongoDB from Deeply Nested JSON Queries
CVE-2026-13064
7.1HIGH
What is CVE-2026-13064?
A vulnerability exists in MongoDB where specific query operations using complex, deeply nested JSON schema constructs can lead to substantial CPU consumption. This situation may result in resource exhaustion, as the operation becomes CPU-bound and cannot be halted through conventional administrative controls, potentially impacting overall system performance.
Affected Version(s)
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12
MongoDB Server 8.3.0 < 8.3.7