VYPR

MongoDB

by MongoDB

Source repositories

CVEs (138)

  • CVE-2026-13057MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded…

  • CVE-2026-5170MedMar 30, 2026
    risk 0.34cvss 5.3epss 0.00

    A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the cluster is being promoted from a replica set to a sharded cluster. This may cause a denial of service by taking…

  • CVE-2025-11979MedOct 20, 2025
    risk 0.34cvss 5.3epss 0.00

    An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to…

  • CVE-2024-6384MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    "Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise…

  • CVE-2024-3374MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB…

  • CVE-2023-1409MedAug 23, 2023
    risk 0.34cvss 5.3epss 0.00

    If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in effect, potentially…

  • CVE-2019-2389MedAug 30, 2019
    risk 0.34cvss 5.3epss 0.00

    Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions…

  • CVE-2025-12657MedNov 3, 2025
    risk 0.33cvss 5.0epss 0.00

    The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

  • CVE-2025-6706MedJun 26, 2025
    risk 0.33cvss 5.0epss 0.00

    An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation…

  • CVE-2024-8654MedSep 10, 2024
    risk 0.33cvss 5.0epss 0.00

    MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

  • CVE-2018-25004MedMar 1, 2021
    risk 0.32cvss 4.9epss 0.01

    A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

  • CVE-2017-2665MedJul 6, 2018
    risk 0.31cvss 4.8epss 0.00

    The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to…

  • CVE-2020-7921MedMay 6, 2020
    risk 0.30cvss 4.6epss 0.01

    Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2…

  • CVE-2025-6711MedJul 7, 2025
    risk 0.29cvss 4.4epss 0.00

    An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB…

  • CVE-2026-13063MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in…

  • CVE-2026-13061MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers,…

  • CVE-2026-8202MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time. This issue impacts MongoDB Server…

  • CVE-2026-13068MedJul 22, 2026
    risk 0.27cvss 4.2epss 0.00

    An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not…

  • CVE-2025-14345MedDec 9, 2025
    risk 0.27cvss 4.2epss 0.00

    A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very short period of time. This error can cause…

  • CVE-2025-12893MedNov 25, 2025
    risk 0.27cvss 4.2epss 0.00

    Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) requirements. A certificate that specifies extendedKeyUsage but is missing extendedKeyUsage = clientAuth may…

Page 6 of 7