Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-13072: MongoDB Compute Mode Memory Corruption in External Data

CVE-2026-13072 · published 2 months ago
Summary

MongoDB's compute mode can be vulnerable to memory corruption if it processes invalid data from external sources. This is a risk if you're using compute mode, but it's not a default setting and requires explicit enablement. To stay safe, ensure you're only using compute mode when necessary and validate any external data being processed.

What to do
  • Update mongodb mongodb server to version 7.0.39 or later.
Affected software
Ecosystem VendorProductAffected versions
– mongodb mongodb server < 7.0.39
Ubuntu:Pro:14.04:LTS canonical mongodb All versions
Ubuntu:Pro:16.04:LTS canonical mongodb All versions
Ubuntu:Pro:18.04:LTS canonical mongodb All versions
Ubuntu:Pro:20.04:LTS canonical mongodb All versions
Original advisory text
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potenti...
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.
Severity
9.2 Critical
CVSS 3.1: 8.1 (MITRE)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published22 Jul 2026
Updated27 Sep 2026
First seen23 Jul 2026
Sources
CVE-2026-13072 · MITRE
Track software like this
Free during beta