{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "4.2.25.tuxcare.els17-r0:\n  - CVE-2026-13061\n  - CVE-2026-13066\n  - CVE-2026-9749\n  - CVE-2026-9752",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.24/advisories/2026/clsa-2026_1788531092.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-11T14:11:48Z",
      "generator": {
        "date": "2026-09-11T14:11:48Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788531092",
      "initial_release_date": "2026-09-04T14:12:33Z",
      "revision_history": [
        {
          "date": "2026-09-04T14:12:33Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-11T12:44:50Z",
          "number": "2",
          "summary": "Update document"
        },
        {
          "date": "2026-09-11T14:11:48Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "mongodb4.2: Fix of 6 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els17-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els16-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els16-r0?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els17-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els16-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els16-r0?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-10060",
      "cwe": {
        "id": "CWE-672",
        "name": "Operation on a Resource after Expiration or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management.  This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10060"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-95524",
          "url": "https://jira.mongodb.org/browse/SERVER-95524"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2025-09-05T21:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-4147",
      "cwe": {
        "id": "CWE-457",
        "name": "Use of Uninitialized Variable"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-4147"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119317",
          "url": "https://jira.mongodb.org/browse/SERVER-119317"
        }
      ],
      "release_date": "2026-03-17T16:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-03-17T16:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-6915",
      "cwe": {
        "id": "CWE-1284",
        "name": "Improper Validation of Specified Quantity in Input"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-6915"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119679",
          "url": "https://jira.mongodb.org/browse/SERVER-119679"
        }
      ],
      "release_date": "2026-04-29T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-04-29T17:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8202",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time.\n\nThis issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8202"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-120668",
          "url": "https://jira.mongodb.org/browse/SERVER-120668"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-05-13T04:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-9752",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.\n\nStrict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9752"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-123440",
          "url": "https://jira.mongodb.org/browse/SERVER-123440"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-13066",
      "cwe": {
        "id": "CWE-843",
        "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments that use server-side JavaScript.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13066"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127694",
          "url": "https://jira.mongodb.org/browse/SERVER-127694"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-07-22T20:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-6914",
      "cwe": {
        "id": "CWE-191",
        "name": "Integer Underflow (Wrap or Wraparound)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.\nThis issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-6914"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119981",
          "url": "https://jira.mongodb.org/browse/SERVER-119981"
        }
      ],
      "release_date": "2026-04-29T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-04-29T17:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-13061",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-13061"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-127689",
          "url": "https://jira.mongodb.org/browse/SERVER-127689"
        }
      ],
      "release_date": "2026-07-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-07-22T20:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-6710",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5.\n\nThe same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6710"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106749",
          "url": "https://jira.mongodb.org/browse/SERVER-106749"
        }
      ],
      "release_date": "2025-06-26T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2025-06-26T14:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-9749",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal \"high watermark\" for that key range is not updated as intended.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9749"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-124031",
          "url": "https://jira.mongodb.org/browse/SERVER-124031"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2024-1351",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections  that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\n\nRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2024-1351"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-72839",
          "url": "https://jira.mongodb.org/browse/SERVER-72839"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240524-0010/",
          "url": "https://security.netapp.com/advisory/ntap-20240524-0010/"
        },
        {
          "category": "external",
          "summary": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024",
          "url": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024"
        },
        {
          "category": "external",
          "summary": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024",
          "url": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024"
        },
        {
          "category": "external",
          "summary": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024",
          "url": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024"
        },
        {
          "category": "external",
          "summary": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024",
          "url": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024"
        }
      ],
      "release_date": "2024-03-07T17:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2024-03-07T17:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-10059",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10059"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100901",
          "url": "https://jira.mongodb.org/browse/SERVER-100901"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100909",
          "url": "https://jira.mongodb.org/browse/SERVER-100909"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2025-09-05T21:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-14847",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "category": "description",
          "text": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-115508",
          "url": "https://jira.mongodb.org/browse/SERVER-115508"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/12/29/21",
          "url": "http://www.openwall.com/lists/oss-security/2025/12/29/21"
        },
        {
          "category": "external",
          "summary": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847",
          "url": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847"
        }
      ],
      "release_date": "2025-12-19T11:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-04T14:11:34.276201Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els17-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els17-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788531092"
        },
        {
          "category": "none_available",
          "date": "2025-12-19T11:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-4.2.25.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.24:mongodb4.2-openrc-4.2.25.tuxcare.els16-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}