{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "4.4.29.tuxcare.els15-r0:\n  - CVE-2026-4147\n  - CVE-2026-11933\n  - CVE-2026-9752\n  - CVE-2025-6713",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.24/advisories/2026/clsa-2026_1787678798.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-25T17:28:06Z",
      "generator": {
        "date": "2026-08-25T17:28:06Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787678798",
      "initial_release_date": "2026-08-25T17:28:06Z",
      "revision_history": [
        {
          "date": "2026-08-25T17:28:06Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "mongodb4.4: Fix of 12 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-7929",
      "cwe": {
        "id": "CWE-185",
        "name": "Incorrect Regular Expression"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2020-7929"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-51083",
          "url": "https://jira.mongodb.org/browse/SERVER-51083"
        }
      ],
      "release_date": "2021-03-01T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-11933",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-11933"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-128125",
          "url": "https://jira.mongodb.org/browse/SERVER-128125"
        }
      ],
      "release_date": "2026-06-12T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13060",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13060"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127357",
          "url": "https://jira.mongodb.org/browse/SERVER-127357"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-4147",
      "cwe": {
        "id": "CWE-457",
        "name": "Use of Uninitialized Variable"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-4147"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119317",
          "url": "https://jira.mongodb.org/browse/SERVER-119317"
        }
      ],
      "release_date": "2026-03-17T16:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-3084",
      "cwe": {
        "id": "CWE-703",
        "name": "Improper Check or Handling of Exceptional Conditions"
      },
      "notes": [
        {
          "category": "description",
          "text": "When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-3084"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-103153",
          "url": "https://jira.mongodb.org/browse/SERVER-103153"
        }
      ],
      "release_date": "2025-04-01T12:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9752",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.\n\nStrict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9752"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123440",
          "url": "https://jira.mongodb.org/browse/SERVER-123440"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13070",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13070"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-128362",
          "url": "https://jira.mongodb.org/browse/SERVER-128362"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13066",
      "cwe": {
        "id": "CWE-843",
        "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13066"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127694",
          "url": "https://jira.mongodb.org/browse/SERVER-127694"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13061",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13061"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127689",
          "url": "https://jira.mongodb.org/browse/SERVER-127689"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-6710",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5.\n\nThe same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6710"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106749",
          "url": "https://jira.mongodb.org/browse/SERVER-106749"
        }
      ],
      "release_date": "2025-06-26T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-13643",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-13643"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-103582",
          "url": "https://jira.mongodb.org/browse/SERVER-103582"
        }
      ],
      "release_date": "2025-11-25T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-6713",
      "cwe": {
        "id": "CWE-285",
        "name": "Improper Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6713"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106752",
          "url": "https://jira.mongodb.org/browse/SERVER-106752"
        }
      ],
      "release_date": "2025-07-07T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:26:40.066535Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678798"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}