What is CVE-2026-13063?
A vulnerability has been identified in MongoDB. An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command, due to insufficient validation of payload-supplied values in the libmongocrypt library. Users are advised to carefully validate inputs and update their MongoDB versions.
Azərbaycanca: Bu boşluq MongoDB-də aşkarlanıb. Standart oxuma/yazma icazəsi olan autentifikasiya olunmuş istifadəçi xüsusi hazırlanmış aggregation komandası göndərərək mongod prosesinin yaddaş çatışmazlığı səbəbindən sonlanmasına səbəb ola bilər. İstifadəçilərə verilənləri diqqətlə yoxlamaq və MongoDB versiyalarını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ1
Through what operation can CVE-2026-13063 cause an out-of-memory condition in MongoDB?
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.