Out-of-Bounds Heap Read in MongoDB Due to Missing Bounds Check
CVE-2026-13077
7.1HIGH
What is CVE-2026-13077?
A vulnerability in MongoDB's BSON CodeWScope element accessors stems from a missing bounds check. This weakness can be exploited by authenticated users through a specially crafted aggregation pipeline, which generates malformed BSONColumn data containing a CodeWScope element. The exploitation process circumvents wire-level BSON validation, leading to the potential for server crashes or the revelation of sensitive adjacent heap memory content during decompression due to unchecked size values used in pointer arithmetic.
Affected Version(s)
MongoDB Server 7.0 < 7.0.39
MongoDB Server 8.0 < 8.0.28
MongoDB Server 8.2.0 < 8.2.12