VYPR

MongoDB

by MongoDB

Source repositories

CVEs (138)

  • CVE-2025-14847HigKEVDec 19, 2025
    risk 0.63cvss 7.5epss 0.83

    Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2…

  • CVE-2017-15535CriNov 1, 2017
    risk 0.59cvss 9.1epss 0.02

    MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify…

  • CVE-2026-8053HigMay 13, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping…

  • CVE-2026-4148HigMar 17, 2026
    risk 0.57cvss 8.8epss 0.00

    A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

  • CVE-2024-1351HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been…

  • CVE-2025-0755HigMar 18, 2025
    risk 0.55cvss 8.4epss 0.01

    The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible…

  • CVE-2026-13059HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and…

  • CVE-2026-9753HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.00

    The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the…

  • CVE-2025-3085HigApr 1, 2025
    risk 0.53cvss 8.1epss 0.00

    A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this…

  • CVE-2019-2390HigAug 30, 2019
    risk 0.53cvss 8.2epss 0.01

    An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server v4.0 versions…

  • CVE-2015-7882HigJul 19, 2019
    risk 0.53cvss 8.1epss 0.02

    Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

  • CVE-2025-6713HigJul 7, 2025
    risk 0.50cvss 7.7epss 0.00

    An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB…

  • CVE-2026-9740HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between…

  • CVE-2026-8336HigMay 13, 2026
    risk 0.49cvss 7.5epss 0.00

    After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce…

  • CVE-2026-1848HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

  • CVE-2026-25611HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

  • CVE-2025-6714HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20…

  • CVE-2025-6710HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server…

  • CVE-2025-6709HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and…

  • CVE-2025-3083HigApr 1, 2025
    risk 0.49cvss 7.5epss 0.00

    Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0…

Page 1 of 7