What is CVE-2026-13064?
CVE-2026-13064 is a vulnerability in MongoDB where specific query operations using deeply nested $jsonSchema constructs can cause disproportionate CPU consumption, leading to resource exhaustion. This CPU-bound operation cannot be interrupted through standard administrative controls, affecting impacted MongoDB deployments. It is recommended to update to the latest patched version to mitigate the issue.
Azərbaycanca: CVE-2026-13064 MongoDB-də dərin iç-içə $jsonSchema konstruksiyalarını əhatə edən sorğu əməliyyatlarının qeyri-mütənasib CPU istehlakına səbəb olması ilə bağlıdır. Bu zəiflik təsirlənmiş MongoDB yerləşdirmələrində resurs tükənməsinə yol aça bilər. Standart inzibati nəzarətlərlə dayandırıla bilməyən bu əməliyyatın qarşısını almaq üçün MongoDB-nin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ2
Which operations in MongoDB cause disproportionate CPU consumption due to CVE-2026-13064?
CVE-2026-13064 causes disproportionate CPU consumption in query operations that involve deeply nested $jsonSchema constructs.
Can the CPU-bound operation caused by CVE-2026-13064 be interrupted through standard administrative controls?
No, this CPU-bound operation cannot be interrupted through standard administrative controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.