Out-of-Bounds Heap Read in MongoDB Due to Missing Bounds Check
CVE-2026-13077

7.1HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
22 July 2026

What is CVE-2026-13077?

A vulnerability in MongoDB's BSON CodeWScope element accessors stems from a missing bounds check. This weakness can be exploited by authenticated users through a specially crafted aggregation pipeline, which generates malformed BSONColumn data containing a CodeWScope element. The exploitation process circumvents wire-level BSON validation, leading to the potential for server crashes or the revelation of sensitive adjacent heap memory content during decompression due to unchecked size values used in pointer arithmetic.

Affected Version(s)

MongoDB Server 7.0 < 7.0.39

MongoDB Server 8.0 < 8.0.28

MongoDB Server 8.2.0 < 8.2.12

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.