← Back to CVE List
CVE-2026-13074NVD
Vulnerability Summary
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- MongoDB MongoDB Server >= 7.0 and < 7.0.39
- MongoDB MongoDB Server >= 8.0 and < 8.0.28
- MongoDB MongoDB Server >= 8.2.0 and < 8.2.12
- MongoDB MongoDB Server >= 8.3.0 and < 8.3.7
- MongoDB MongoDB Server 7.0.39
- MongoDB MongoDB Server 8.0.28
- MongoDB MongoDB Server 8.2.12
- MongoDB MongoDB Server 8.3.7