CVE-2026-13074

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.
Configurations

No configuration.

History

22 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-22 20:16

Updated : 2026-07-23 15:33


NVD link : CVE-2026-13074

Mitre link : CVE-2026-13074

CVE.ORG link : CVE-2026-13074


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling