VYPR

Server

by MongoDB

Source repositories

CVEs (73)

  • CVE-2023-1409MedAug 23, 2023
    risk 0.34cvss 5.3epss 0.00

    If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in effect, potentially…

  • CVE-2019-2389MedAug 30, 2019
    risk 0.34cvss 5.3epss 0.00

    Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions…

  • CVE-2025-6706MedJun 26, 2025
    risk 0.33cvss 5.0epss 0.00

    An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation…

  • CVE-2024-8654MedSep 10, 2024
    risk 0.33cvss 5.0epss 0.00

    MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

  • CVE-2018-25004MedMar 1, 2021
    risk 0.32cvss 4.9epss 0.01

    A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

  • CVE-2020-7921MedMay 6, 2020
    risk 0.30cvss 4.6epss 0.01

    Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2…

  • CVE-2025-6711MedJul 7, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB…

  • CVE-2025-14345MedDec 9, 2025
    risk 0.27cvss 4.2epss 0.00

    A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very short period of time. This error can cause…

  • CVE-2025-12893MedNov 25, 2025
    risk 0.27cvss 4.2epss 0.00

    Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) requirements. A certificate that specifies extendedKeyUsage but is missing extendedKeyUsage = clientAuth may…

  • CVE-2025-6707MedJun 26, 2025
    risk 0.27cvss 4.2epss 0.00

    Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.24, MongoDB Server…

  • CVE-2025-13643LowNov 25, 2025
    risk 0.20cvss 3.1epss 0.00

    A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB…

  • CVE-2025-3082LowApr 1, 2025
    risk 0.20cvss 3.1epss 0.00

    A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB…

  • CVE-2026-1849Feb 10, 2026
    risk 0.00cvss epss 0.00

    MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

Page 4 of 4