What is CVE-2026-13070?
The MongoDB server may terminate abnormally when processing a malformed OCSP response from a remote peer during an outbound TLS handshake. This vulnerability impacts all configurations where OCSP stapling validation is enabled by default for outgoing connections. Network-level filtering should be applied to protect against untrusted certificate responses during the TLS handshake, and the MongoDB version should be updated.
Azərbaycanca: MongoDB server-i xarici TLS bağlantısı zamanı uzaq tərəfin göndərdiyi zədəli OCSP cavabını emal edərkən anormal şəkildə sonlanır. Bu zəiflik, serverin OCSP stapling yoxlamasının standart olaraq aktiv olduğu bütün konfiqurasiyalara təsir edir. TLS əl sıxışması zamanı etibarlı olmayan sertifikat cavablarından qorunmaq üçün şəbəkə səviyyəsində filtrasiya tətbiq edilməli və MongoDB versiyası yenilənməlidir.
Related CVEs
link basis: shared vendor: MongoDB
FAQ2
During which network operation does the CVE-2026-13070 vulnerability occur in MongoDB?
This vulnerability occurs when the MongoDB server processes a malformed OCSP response from a remote peer during an outbound TLS handshake.
What primary measure is recommended to mitigate the CVE-2026-13070 vulnerability?
Network-level filtering should be applied to protect against untrusted certificate responses during the TLS handshake, and the MongoDB version should be updated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.