VYPR

MongoDB

by MongoDB

Source repositories

CVEs (149)

  • CVE-2025-6714HigJul 7, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20…

  • CVE-2025-6710HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.00

    MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server…

  • CVE-2025-6709HigJun 26, 2025
    risk 0.49cvss 7.5epss 0.01

    The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and…

  • CVE-2025-3083HigApr 1, 2025
    risk 0.49cvss 7.5epss 0.00

    Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0…

  • CVE-2020-7925HigNov 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB…

  • CVE-2017-14227HigSep 9, 2017
    risk 0.49cvss 7.5epss 0.03

    In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as…

  • CVE-2016-3104HigApr 14, 2017
    risk 0.49cvss 7.5epss 0.02

    mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

  • CVE-2024-7553HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue…

  • CVE-2026-18711HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could…

  • CVE-2026-13077HigJul 22, 2026
    risk 0.46cvss 7.1epss 0.00

    A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a…

  • CVE-2019-2386HigAug 6, 2019
    risk 0.46cvss 7.1epss 0.01

    After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions…

  • CVE-2024-10921MedNov 14, 2024
    risk 0.44cvss 6.8epss 0.01

    An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the MongoDB Server. This issue affects MongoDB Server v5.0 versions prior to 5.0.30 , MongoDB Server v6.0…

  • CVE-2026-82058MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jsonSchema items type constraint, the error…

  • CVE-2026-82057MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during collection creation, a user could cause a type…

  • CVE-2026-82055MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geometry parsing can leave an…

  • CVE-2026-82052MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion…

  • CVE-2026-18701MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.

  • CVE-2026-18700MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator.…

  • CVE-2026-13076MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during…

  • CVE-2026-13075MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and requires the ability to run aggregation queries.

Page 2 of 8