Looking for the vulnerability index of Invicti's legacy products?
MongoDb NULL Pointer Dereference Vulnerability (CVE-2026-13065) - Vulnerability Database

MongoDb NULL Pointer Dereference Vulnerability (CVE-2026-13065)

Description

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort specifications during execution.

References