{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "5.0.31.tuxcare.els15-r0:\n  - CVE-2026-9753\n  - CVE-2026-9749\n  - CVE-2026-9752\n  - CVE-2026-9740\n  - CVE-2026-9750",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.24/advisories/2026/clsa-2026_1787680669.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-04T13:14:18Z",
      "generator": {
        "date": "2026-09-04T13:14:18Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787680669",
      "initial_release_date": "2026-08-25T17:59:05Z",
      "revision_history": [
        {
          "date": "2026-08-25T17:59:05Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-04T13:14:18Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "mongodb5: Fix of 9 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb5-openrc@5.0.31.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb5@5.0.31.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb5-openrc@5.0.31.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb5@5.0.31.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb5-5.0.31.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb5-5.0.31.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-10061",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability could lead to denial of service if triggered repeatedly. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22, MongoDB Server v8.0 versions prior to 8.0.12 and MongoDB Server v8.1 versions prior to 8.1.2",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10061"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-99616",
          "url": "https://jira.mongodb.org/browse/SERVER-99616"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-1849",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-1849"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-102364",
          "url": "https://jira.mongodb.org/browse/SERVER-102364"
        }
      ],
      "release_date": "2026-02-10T19:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-10060",
      "cwe": {
        "id": "CWE-672",
        "name": "Operation on a Resource after Expiration or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management.  This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10060"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-95524",
          "url": "https://jira.mongodb.org/browse/SERVER-95524"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13060",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios involve collections referenced within existing view pipeline definitions.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13060"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127357",
          "url": "https://jira.mongodb.org/browse/SERVER-127357"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9750",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9750"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123633",
          "url": "https://jira.mongodb.org/browse/SERVER-123633"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9740",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9740"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-125063",
          "url": "https://jira.mongodb.org/browse/SERVER-125063"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9752",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.\n\nStrict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9752"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123440",
          "url": "https://jira.mongodb.org/browse/SERVER-123440"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13070",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13070"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-128362",
          "url": "https://jira.mongodb.org/browse/SERVER-128362"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13066",
      "cwe": {
        "id": "CWE-843",
        "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13066"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127694",
          "url": "https://jira.mongodb.org/browse/SERVER-127694"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6914",
      "cwe": {
        "id": "CWE-191",
        "name": "Integer Underflow (Wrap or Wraparound)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.\nThis issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-6914"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119981",
          "url": "https://jira.mongodb.org/browse/SERVER-119981"
        }
      ],
      "release_date": "2026-04-29T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-6711",
      "cwe": {
        "id": "CWE-532",
        "name": "Insertion of Sensitive Information into Log File"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v6.0 versions prior to 6.0.21.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6711"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-98720",
          "url": "https://jira.mongodb.org/browse/SERVER-98720"
        }
      ],
      "release_date": "2025-07-07T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-13061",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13061"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127689",
          "url": "https://jira.mongodb.org/browse/SERVER-127689"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-25609",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-25609"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-112952",
          "url": "https://jira.mongodb.org/browse/SERVER-112952"
        }
      ],
      "release_date": "2026-02-10T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-6710",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5.\n\nThe same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6710"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106749",
          "url": "https://jira.mongodb.org/browse/SERVER-106749"
        }
      ],
      "release_date": "2025-06-26T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9749",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal \"high watermark\" for that key range is not updated as intended.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9749"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-124031",
          "url": "https://jira.mongodb.org/browse/SERVER-124031"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-9753",
      "cwe": {
        "id": "CWE-1287",
        "name": "Improper Validation of Specified Type of Input"
      },
      "notes": [
        {
          "category": "description",
          "text": "The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9753"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-124959",
          "url": "https://jira.mongodb.org/browse/SERVER-124959"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-10059",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10059"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100901",
          "url": "https://jira.mongodb.org/browse/SERVER-100901"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100909",
          "url": "https://jira.mongodb.org/browse/SERVER-100909"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-14847",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "category": "description",
          "text": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-115508",
          "url": "https://jira.mongodb.org/browse/SERVER-115508"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/12/29/21",
          "url": "http://www.openwall.com/lists/oss-security/2025/12/29/21"
        },
        {
          "category": "external",
          "summary": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847",
          "url": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847"
        }
      ],
      "release_date": "2025-12-19T11:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-13643",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-13643"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-103582",
          "url": "https://jira.mongodb.org/browse/SERVER-103582"
        }
      ],
      "release_date": "2025-11-25T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-6713",
      "cwe": {
        "id": "CWE-285",
        "name": "Improper Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6713"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106752",
          "url": "https://jira.mongodb.org/browse/SERVER-106752"
        }
      ],
      "release_date": "2025-07-07T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T17:57:51.157382Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-5.0.31.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.24:mongodb5-openrc-5.0.31.tuxcare.els15-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1787680669"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}