{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "6.0.26.tuxcare.els18-r0:\n  - CVE-2026-9750\n  - CVE-2026-9740\n  - CVE-2026-9751\n  - CVE-2025-13643",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.24/advisories/2026/clsa-2026_1787678477.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-04T13:03:54Z",
      "generator": {
        "date": "2026-09-04T13:03:54Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787678477",
      "initial_release_date": "2026-08-25T17:22:05Z",
      "revision_history": [
        {
          "date": "2026-08-25T17:22:05Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-04T13:03:54Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "mongodb6: Fix of 4 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els18-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els18-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els18-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els18-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els18-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els18-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-4358",
      "cwe": {
        "id": "CWE-415",
        "name": "Double Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-4358"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-118849",
          "url": "https://jira.mongodb.org/browse/SERVER-118849"
        }
      ],
      "release_date": "2026-03-17T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-03-17T20:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-1849",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-1849"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-102364",
          "url": "https://jira.mongodb.org/browse/SERVER-102364"
        }
      ],
      "release_date": "2026-02-10T19:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-02-10T19:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-11933",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-11933"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-128125",
          "url": "https://jira.mongodb.org/browse/SERVER-128125"
        }
      ],
      "release_date": "2026-06-12T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-06-12T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9751",
      "cwe": {
        "id": "CWE-532",
        "name": "Insertion of Sensitive Information into Log File"
      },
      "notes": [
        {
          "category": "description",
          "text": "The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9751"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123370",
          "url": "https://jira.mongodb.org/browse/SERVER-123370"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9750",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9750"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123633",
          "url": "https://jira.mongodb.org/browse/SERVER-123633"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9740",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9740"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-125063",
          "url": "https://jira.mongodb.org/browse/SERVER-125063"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-8199",
      "cwe": {
        "id": "CWE-1325",
        "name": "Improperly Controlled Sequential Memory Allocation"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM.\n\nThis issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8199"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-122449",
          "url": "https://jira.mongodb.org/browse/SERVER-122449"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-05-13T04:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-13644",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-13644"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-101180",
          "url": "https://jira.mongodb.org/browse/SERVER-101180"
        }
      ],
      "release_date": "2025-11-25T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2025-11-25T06:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6914",
      "cwe": {
        "id": "CWE-191",
        "name": "Integer Underflow (Wrap or Wraparound)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.\nThis issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-6914"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119981",
          "url": "https://jira.mongodb.org/browse/SERVER-119981"
        }
      ],
      "release_date": "2026-04-29T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2026-04-29T17:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-13643",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-13643"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-103582",
          "url": "https://jira.mongodb.org/browse/SERVER-103582"
        }
      ],
      "release_date": "2025-11-25T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:21:19.383764Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els18-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els18-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787678477"
        },
        {
          "category": "none_available",
          "date": "2025-11-25T06:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-6.0.26.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb6-openrc-6.0.26.tuxcare.els17-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}