CVE-2026-13066: Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13066?
The severity of CVE-2026-13066 is rated as medium with a score of 6.5.
How do I fix CVE-2026-13066?
To fix CVE-2026-13066, update MongoDB to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-13066?
CVE-2026-13066 can lead to internal process memory contents being disclosed to clients, resulting in information leakage.
Who is affected by CVE-2026-13066?
Deployments using MongoDB's server-side JavaScript engine that improperly handle DBPointer objects are affected by CVE-2026-13066.
What software is impacted by CVE-2026-13066?
CVE-2026-13066 impacts the MongoDB Server-side JavaScript engine.