{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "6.0.26.tuxcare.els17-r0:\n  - CVE-2026-13070\n  - CVE-2026-13060\n  - CVE-2026-9753\n  - CVE-2026-9752",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.24/advisories/2026/clsa-2026_1787221489.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-20T12:35:59Z",
      "generator": {
        "date": "2026-08-20T12:35:59Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787221489",
      "initial_release_date": "2026-08-20T10:25:19Z",
      "revision_history": [
        {
          "date": "2026-08-20T10:25:19Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-20T11:15:00Z",
          "number": "2",
          "summary": "Update document"
        },
        {
          "date": "2026-08-20T12:35:59Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "mongodb6: Fix of CVE-2026-25609"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-4147",
      "cwe": {
        "id": "CWE-457",
        "name": "Use of Uninitialized Variable"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-4147"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119317",
          "url": "https://jira.mongodb.org/browse/SERVER-119317"
        }
      ],
      "release_date": "2026-03-17T16:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-20T10:24:51.167204Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8202",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time.\n\nThis issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8202"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-120668",
          "url": "https://jira.mongodb.org/browse/SERVER-120668"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-20T10:24:51.167204Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-25609",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-25609"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-112952",
          "url": "https://jira.mongodb.org/browse/SERVER-112952"
        }
      ],
      "release_date": "2026-02-10T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-20T10:24:51.167204Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8053",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution.\n\nThis issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8053"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-126021",
          "url": "https://jira.mongodb.org/browse/SERVER-126021"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-20T10:24:51.167204Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787221489"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}