VYPR
Medium severity6.5NVD Advisory· Published Jul 22, 2026· Updated Aug 5, 2026

CVE-2026-13055

CVE-2026-13055

Description

The $_internalIndexKey aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • MongoDB/MongoDB2 versions
    cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*range: >=7.0.0,<7.0.39
    • (no CPE)
  • osv-coords
    Range: >= 7.0.0, < 7.0.39

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.