Vulnerability Bulletins |
CVE-2026-13066 |
|
| Affected software | MONGODB |
| Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-13066 | |






