What is CVE-2026-13074?
CVE-2026-13074 is a vulnerability that allows an unauthenticated remote client to cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode, bypassing normal throttling via a response loop. This can lead to service disruption. Updating affected MongoDB servers is recommended.
Azərbaycanca: CVE-2026-13074 MongoDB serverdə autentifikasiya olunmamış uzaq müştərinin awaitable hello əmrini exhaust rejimində xüsusi parametrlərlə göndərərək həddindən artıq CPU istehlakına səbəb olmasına imkan verən zəiflikdir. Bu, cavab dövrü yaradaraq normal tənzimləməni keçərək xidmətə əngəl törədə bilər. Təsirlənən MongoDB serverlərini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: MongoDB
FAQ1
How can CVE-2026-13074 affect a MongoDB server?
This vulnerability allows an unauthenticated remote client to cause excessive CPU consumption by sending a specific combination of parameters to the awaitable hello command in exhaust mode. This creates a response loop that bypasses normal throttling, potentially leading to service disruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.