VYPR
Unrated severityNVD Advisory· Published Jul 22, 2026· Updated Jul 23, 2026

MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination

CVE-2026-13065

Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.