VYPR

Server

by MongoDB

Source repositories

CVEs (114)

  • CVE-2018-25004MedMar 1, 2021
    risk 0.32cvss 4.9epss 0.01

    A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

  • CVE-2020-7921MedMay 6, 2020
    risk 0.30cvss 4.6epss 0.01

    Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2…

  • CVE-2025-6711MedJul 7, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB…

  • CVE-2026-18707MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.

  • CVE-2026-8202MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time. This issue impacts MongoDB Server…

  • CVE-2026-18703MedAug 11, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms.…

  • CVE-2026-13068MedJul 22, 2026
    risk 0.27cvss 4.2epss 0.00

    An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not…

  • CVE-2025-14345MedDec 9, 2025
    risk 0.27cvss 4.2epss 0.00

    A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very short period of time. This error can cause…

  • CVE-2025-12893MedNov 25, 2025
    risk 0.27cvss 4.2epss 0.00

    Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) requirements. A certificate that specifies extendedKeyUsage but is missing extendedKeyUsage = clientAuth may…

  • CVE-2025-6707MedJun 26, 2025
    risk 0.27cvss 4.2epss 0.00

    Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.24, MongoDB Server…

  • CVE-2025-13643LowNov 25, 2025
    risk 0.20cvss 3.1epss 0.00

    A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB…

  • CVE-2025-3082LowApr 1, 2025
    risk 0.20cvss 3.1epss 0.00

    A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB…

  • CVE-2026-82069LowSep 8, 2026
    risk 0.18cvss 2.7epss 0.00

    A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other users' operations. An improper conditional check in the serialization logic causes the data redaction…

  • CVE-2026-8200LowMay 13, 2026
    risk 0.18cvss 2.7epss 0.00

    When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.  This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior…

Page 6 of 6