{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.23/vex/2026/cve-2026-8053-els_docker-alpinelinux3_23.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-23T02:22:49Z",
      "generator": {
        "date": "2026-06-23T02:22:49Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-8053-ELS_DOCKER-ALPINELINUX3.23",
      "initial_release_date": "2026-05-13T04:17:00Z",
      "revision_history": [
        {
          "date": "2026-05-13T04:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-23T02:22:49Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-8053"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.23",
                "product": {
                  "name": "Alpine Linux 3.23",
                  "product_id": "Alpine-Linux-3.23",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.23:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els10-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els10-r0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els10-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els10-r0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-8053",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution.\n\nThis issue impacts MongoDB Server v5.0 versions prior to 5.0.33, v6.0 versions prior to 6.0.28, v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "under_investigation": [
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8053"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-126021",
          "url": "https://jira.mongodb.org/browse/SERVER-126021"
        }
      ],
      "release_date": "2026-05-13T04:17:00Z",
      "remediations": [
        {
          "category": "none_available",
          "date": "2026-05-27T12:19:39.187801Z",
          "details": "Affected",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-r0.x86_64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-r0.x86_64"
          ]
        }
      ]
    }
  ]
}