{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "4.4.29.tuxcare.els16-r0:\n  - CVE-2026-9749",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.23/advisories/2026/clsa-2026_1788268374.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-11T12:31:24Z",
      "generator": {
        "date": "2026-09-11T12:31:24Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788268374",
      "initial_release_date": "2026-09-01T13:13:28Z",
      "revision_history": [
        {
          "date": "2026-09-01T13:13:28Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-04T12:04:08Z",
          "number": "2",
          "summary": "Update document"
        },
        {
          "date": "2026-09-11T12:31:24Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "mongodb4.4: Fix of CVE-2026-9749"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.23",
                "product": {
                  "name": "Alpine Linux 3.23",
                  "product_id": "Alpine-Linux-3.23",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.23:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els16-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els16-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els15-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els16-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els16-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4@4.4.29.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                "product": {
                  "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_id": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.4-openrc@4.4.29.tuxcare.els15-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64"
        },
        "product_reference": "mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-10061",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability could lead to denial of service if triggered repeatedly. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22, MongoDB Server v8.0 versions prior to 8.0.12 and MongoDB Server v8.1 versions prior to 8.1.2",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10061"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-99616",
          "url": "https://jira.mongodb.org/browse/SERVER-99616"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2025-09-05T21:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-1849",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-1849"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-102364",
          "url": "https://jira.mongodb.org/browse/SERVER-102364"
        }
      ],
      "release_date": "2026-02-10T19:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-02-10T19:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-10060",
      "cwe": {
        "id": "CWE-672",
        "name": "Operation on a Resource after Expiration or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management.  This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10060"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-95524",
          "url": "https://jira.mongodb.org/browse/SERVER-95524"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2025-09-05T21:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-8202",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time.\n\nThis issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8202"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-120668",
          "url": "https://jira.mongodb.org/browse/SERVER-120668"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-05-13T04:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-8199",
      "cwe": {
        "id": "CWE-1325",
        "name": "Improperly Controlled Sequential Memory Allocation"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM.\n\nThis issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8199"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-122449",
          "url": "https://jira.mongodb.org/browse/SERVER-122449"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-05-13T04:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-6914",
      "cwe": {
        "id": "CWE-191",
        "name": "Integer Underflow (Wrap or Wraparound)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server.\nThis issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 versions prior to 8.0.21, MongoDB Server v7.0 versions prior to 7.0.32",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-6914"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-119981",
          "url": "https://jira.mongodb.org/browse/SERVER-119981"
        }
      ],
      "release_date": "2026-04-29T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-04-29T17:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-8336",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.\n\nThis issue impacts MongoDB Server v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-8336"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-121610",
          "url": "https://jira.mongodb.org/browse/SERVER-121610"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-05-13T04:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-25609",
      "cwe": {
        "id": "CWE-862",
        "name": "Missing Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-25609"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-112952",
          "url": "https://jira.mongodb.org/browse/SERVER-112952"
        }
      ],
      "release_date": "2026-02-10T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-02-10T19:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-9749",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal \"high watermark\" for that key range is not updated as intended.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
        ],
        "known_affected": [
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2026-9749"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-124031",
          "url": "https://jira.mongodb.org/browse/SERVER-124031"
        }
      ],
      "release_date": "2026-06-09T23:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-01T13:12:56.621061Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els16-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els16-r0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1788268374"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T23:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-4.4.29.tuxcare.els15-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.4-openrc-4.4.29.tuxcare.els15-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}