TLS Handshake Vulnerability in MongoDB Server by MongoDB Inc.
CVE-2026-13070

6MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13070?

A flaw in MongoDB Server allows for abnormal termination when handling malformed OCSP responses from remote peers during TLS handshake processes. The issue occurs when OCSP stapling validation is enabled and requires the remote peer to present a certificate from a trusted certificate authority of the MongoDB cluster. Furthermore, these circumstances could be exacerbated by traversing untrusted network paths, introducing significant security concerns for applications relying on secure database connections.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.