TLS Handshake Vulnerability in MongoDB Server by MongoDB Inc.
CVE-2026-13070
6MEDIUM
What is CVE-2026-13070?
A flaw in MongoDB Server allows for abnormal termination when handling malformed OCSP responses from remote peers during TLS handshake processes. The issue occurs when OCSP stapling validation is enabled and requires the remote peer to present a certificate from a trusted certificate authority of the MongoDB cluster. Furthermore, these circumstances could be exacerbated by traversing untrusted network paths, introducing significant security concerns for applications relying on secure database connections.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12