目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-13066— Server-Side JavaScript DBPointer BSON序列化内存泄露漏洞

CVSS 6.5 · Medium EPSS 0.38% · P30

Possible ATT&CK Techniques 1AI

T1005 · Data from Local System

Affected Version Matrix 4

ベンダープロダクトVersion Rangeステータス
MongoDBMongoDB Server7.0< 7.0.39affected
8.0< 8.0.28affected
8.2.0< 8.2.12affected
8.3.0< 8.3.7affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-13066の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure
ソース: CVE Program / CVE List V5
脆弱性説明
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
使用不兼容类型访问资源(类型混淆)
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
MongoDBMongoDB Server 7.0 ~ 7.0.39 -

II. CVE-2026-13066の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-13066のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · MongoDB · 2026-07-22 · 26 CVEs total

CVE-2026-130598.1 HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Contr
CVE-2026-130728.1 HIGHMongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memo
CVE-2026-148817.8 HIGHCompass connection import allows to override OIDC browser open command (usually set throug
CVE-2026-130787.7 HIGHLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader
CVE-2026-130777.1 HIGHOut-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data
CVE-2026-130587.1 HIGHTransaction Command Insufficient Input Validation Leading to Process Termination
CVE-2026-130566.5 MEDIUMA user with read access can cause a DoS by executing a specifically crafted query to consu
CVE-2026-130626.5 MEDIUMMongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Command
CVE-2026-130606.5 MEDIUM$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Col
CVE-2026-130756.5 MEDIUM$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generatio
CVE-2026-130656.5 MEDIUMMongoDB $linearFill Window Function Improper Input Validation Leading to Process Terminati
CVE-2026-130556.5 MEDIUMServer crash via aggregation pipeline expression with compound wildcard index specificatio
CVE-2026-130696.5 MEDIUMQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaus
CVE-2026-97376.5 MEDIUMFind command with $meta sort can lead to crash
CVE-2026-130646.5 MEDIUMMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service
CVE-2026-130766.5 MEDIUMAggregation Framework Memory Exhaustion Leading to Process Termination
CVE-2026-130716.5 MEDIUMServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termi
CVE-2026-130676.3 MEDIUMtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket
CVE-2026-130575.3 MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collec
CVE-2026-130705.3 MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Term

Showing 20 of 26 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-13066へのコメント

まだコメントはありません


コメントを残す