[Git][security-tracker-team/security-tracker][master] Add new batch of monbodb issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 22:17:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d8f70864 by Salvatore Bonaccorso at 2026-07-24T23:16:34+02:00
Add new batch of monbodb issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1448,53 +1448,77 @@ CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does no
CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
NOT-FOR-US: OIDC::Lite Perl module
CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128832
CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element accessors allows ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-129103
CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be terminated ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128584
CVE-2026-13075 (An authenticated user can cause the mongod process to be terminated by ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128316
CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU consumption o ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128517
CVE-2026-13073 (An authenticated user with read-only privileges can cause the mongod p ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128512
CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance, insuffic ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128494
CVE-2026-13071 (An authenticated user with read access can cause the mongod process to ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128473
CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may terminate a ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128362
CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or out-of-me ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127566
CVE-2026-13068 (An authenticated user holding cursor termination privileges on one dat ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128198
CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path, roles d ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128387
CVE-2026-13066 (Improper handling of DBPointer objects during BSON serialization in Mo ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127694
CVE-2026-13065 (A user with read-only privileges is able to craft an aggregation pipel ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127280
CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema construct ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-125872
CVE-2026-13063 (An authenticated user with standard read/write privileges can cause th ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127737
CVE-2026-13062 (An authenticated user with write privileges on a Queryable Encryption- ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127831
CVE-2026-13061 (An authenticated user may be able to view session metadata belonging t ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127689
CVE-2026-13060 (An authenticated user with limited read privileges may be able to acce ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127357
CVE-2026-13059 (An authenticated user with low privileges may be able to perform unaut ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128433
CVE-2026-13058 (An authenticated user with basic write privileges can cause the mongod ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127661
CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows an authe ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-126247
CVE-2026-13056 (Using expressions that generate large arrays it is possible to craft a ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-124355
CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by any aut ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-123081
CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not perform auth ...)
NOT-FOR-US: WordPress plugin
CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows attackers to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/21f47cef/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list