CVE-2026-13064: MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13064?
CVE-2026-13064 has a severity score of medium, rated at 6.5.
How do I fix CVE-2026-13064?
To mitigate CVE-2026-13064, monitor your queries for deeply nested $jsonSchema constructs and consider optimizing your query structure.
What type of attack does CVE-2026-13064 facilitate?
CVE-2026-13064 can facilitate a Denial of Service (DoS) attack due to excessive CPU consumption.
Which software is affected by CVE-2026-13064?
CVE-2026-13064 affects MongoDB deployments that use the $jsonSchema query operator.
What are the potential impacts of CVE-2026-13064?
The potential impact of CVE-2026-13064 includes resource exhaustion, leading to a significant decrease in system performance or availability.