VYPR

MongoDB

by MongoDB

Source repositories

CVEs (149)

  • CVE-2025-14847HigKEVDec 19, 2025
    risk 0.63cvss 7.5epss 0.83

    Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2…

  • CVE-2017-15535CriNov 1, 2017
    risk 0.59cvss 9.1epss 0.02

    MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify…

  • CVE-2026-8053HigMay 13, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping…

  • CVE-2026-4148HigMar 17, 2026
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

  • CVE-2024-1351HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been…

  • CVE-2025-0755HigMar 18, 2025
    risk 0.55cvss 8.4epss 0.01

    The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible…

  • CVE-2026-82053HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity…

  • CVE-2026-13072HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This…

  • CVE-2026-13059HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and…

  • CVE-2026-9753HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the…

  • CVE-2025-3085HigApr 1, 2025
    risk 0.53cvss 8.1epss 0.00

    A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this…

  • CVE-2019-2390HigAug 30, 2019
    risk 0.53cvss 8.2epss 0.01

    An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server v4.0 versions…

  • CVE-2015-7882HigJul 19, 2019
    risk 0.53cvss 8.1epss 0.02

    Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

  • CVE-2026-13078HigJul 22, 2026
    risk 0.50cvss 7.7epss 0.00

    A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated…

  • CVE-2025-6713HigJul 7, 2025
    risk 0.50cvss 7.7epss 0.00

    An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB…

  • CVE-2026-82075HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to…

  • CVE-2026-9740HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between…

  • CVE-2026-8336HigMay 13, 2026
    risk 0.49cvss 7.5epss 0.00

    After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce…

  • CVE-2026-1848HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

  • CVE-2026-25611HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

Page 1 of 8