Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d8f70864 by Salvatore Bonaccorso at 2026-07-24T23:16:34+02:00
Add new batch of monbodb issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1448,53 +1448,77 @@ CVE-2026-14291 (The security-ninja-premium WordPress
plugin before 5.290 does no
CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token
signature v ...)
NOT-FOR-US: OIDC::Lite Perl module
CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the
server-side ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128832
CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element
accessors allows ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-129103
CVE-2026-13076 (An authenticated user can cause a {{mongod}} process to be
terminated ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128584
CVE-2026-13075 (An authenticated user can cause the mongod process to be
terminated by ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128316
CVE-2026-13074 (An unauthenticated remote client can cause excessive CPU
consumption o ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128517
CVE-2026-13073 (An authenticated user with read-only privileges can cause the
mongod p ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128512
CVE-2026-13072 (When compute mode is enabled on a standalone mongod instance,
insuffic ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128494
CVE-2026-13071 (An authenticated user with read access can cause the mongod
process to ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128473
CVE-2026-13070 (A MongoDB server initiating an outbound TLS connection may
terminate a ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128362
CVE-2026-13069 (An authenticated user can cause excessive CPU consumption or
out-of-me ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127566
CVE-2026-13068 (An authenticated user holding cursor termination privileges on
one dat ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128198
CVE-2026-13067 (When PROXY protocol v2 is used on the Unix domain socket path,
roles d ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128387
CVE-2026-13066 (Improper handling of DBPointer objects during BSON
serialization in Mo ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127694
CVE-2026-13065 (A user with read-only privileges is able to craft an
aggregation pipel ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127280
CVE-2026-13064 (Certain query operations involving deeply nested $jsonSchema
construct ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-125872
CVE-2026-13063 (An authenticated user with standard read/write privileges can
cause th ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127737
CVE-2026-13062 (An authenticated user with write privileges on a Queryable
Encryption- ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127831
CVE-2026-13061 (An authenticated user may be able to view session metadata
belonging t ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127689
CVE-2026-13060 (An authenticated user with limited read privileges may be able
to acce ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127357
CVE-2026-13059 (An authenticated user with low privileges may be able to
perform unaut ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-128433
CVE-2026-13058 (An authenticated user with basic write privileges can cause
the mongod ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-127661
CVE-2026-13057 (An issue in the server\u2019s Atlas Search integration allows
an authe ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-126247
CVE-2026-13056 (Using expressions that generate large arrays it is possible to
craft a ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-124355
CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by
any aut ...)
- TODO: check
+ - mongodb <removed>
+ NOTE: https://jira.mongodb.org/browse/SERVER-123081
CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not
perform auth ...)
NOT-FOR-US: WordPress plugin
CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows
attackers to ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d8f70864db802cdaf0547cf99d21d6c59a228b73
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits