VYPR

Server

by MongoDB

Source repositories

CVEs (114)

  • CVE-2026-9740HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between…

  • CVE-2026-8336HigMay 13, 2026
    risk 0.49cvss 7.5epss 0.00

    After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce…

  • CVE-2026-1848HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

  • CVE-2025-6714HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20…

  • CVE-2025-6710HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server…

  • CVE-2025-6709HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and…

  • CVE-2020-7925HigNov 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB…

  • CVE-2024-7553HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue…

  • CVE-2026-18711HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could…

  • CVE-2026-18694HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the…

  • CVE-2026-18688HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may…

  • CVE-2026-18687HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed…

  • CVE-2026-13077HigJul 22, 2026
    risk 0.46cvss 7.1epss 0.00

    A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a…

  • CVE-2019-2386HigAug 6, 2019
    risk 0.46cvss 7.1epss 0.01

    After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions…

  • CVE-2024-10921MedNov 14, 2024
    risk 0.44cvss 6.8epss 0.01

    An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the MongoDB Server. This issue affects MongoDB Server v5.0 versions prior to 5.0.30 , MongoDB Server v6.0…

  • CVE-2026-18706MedAug 11, 2026
    risk 0.43cvss 6.6epss 0.00

    An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or,…

  • CVE-2026-18709MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency,…

  • CVE-2026-18708MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance…

  • CVE-2026-18704MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients…

  • CVE-2026-18702MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide,…

Page 2 of 6