Unrated severityNVD Advisory· Published Jul 22, 2026· Updated Jul 23, 2026
Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion
CVE-2026-13069
Description
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.