SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13064

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

MongoDB deployments are vulnerable to excessive CPU consumption due to certain query operations involving deeply nested $jsonSchema constructs, which can lead to resource exhaustion. This vulnerability can cause significant performance degradation, as the CPU-bound operation cannot be interrupted through standard administrative controls. Organizations using MongoDB should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-13064
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
MongoDB

Original NVD Description

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls.

Related CVEs

Other vulnerabilities affecting the same vendor(s)