VYPR

Vendor CVEs

MongoDB

All CVEs

223 total · sorted by risk
  • CVE-2026-1847MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the oplog from the primary. This could stall replication inside the replica set leading to server crash.

  • CVE-2026-25612MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.

  • CVE-2025-14911MedJan 27, 2026
    risk 0.42cvss 6.5epss 0.00

    User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overflow the bounding container.

  • CVE-2025-13644MedNov 25, 2025
    risk 0.42cvss 6.5epss 0.00

    MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue…

  • CVE-2025-13507MedNov 25, 2025
    risk 0.42cvss 6.5epss 0.00

    Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16…

  • CVE-2025-10061MedSep 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability…

  • CVE-2025-10060MedSep 5, 2025
    risk 0.42cvss 6.5epss 0.00

    MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects…

  • CVE-2025-10059MedSep 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0…

  • CVE-2025-7259MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.

  • CVE-2025-6712MedJul 7, 2025
    risk 0.42cvss 6.5epss 0.00

    MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal operations. In scenarios where certain internal processes persist longer than…

  • CVE-2025-3084MedApr 1, 2025
    risk 0.42cvss 6.5epss 0.00

    When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16…

  • CVE-2024-8305MedOct 21, 2024
    risk 0.42cvss 6.5epss 0.01

    prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primaries. This issue affects MongoDB Server v6.0 versions prior to 6.0.17, MongoDB…

  • CVE-2024-8207MedAug 27, 2024
    risk 0.42cvss 6.4epss 0.00

    In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared…

  • CVE-2024-3372HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server…

  • CVE-2022-24272MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and…

  • CVE-2021-32040MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.02

    It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously…

  • CVE-2021-20330MedDec 15, 2021
    risk 0.42cvss 6.5epss 0.01

    An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2…

  • CVE-2021-32037MedNov 24, 2021
    risk 0.42cvss 6.5epss 0.01

    An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to…

  • CVE-2021-20326MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.

  • CVE-2020-7929MedMar 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.

  • CVE-2021-20328MedFeb 25, 2021
    risk 0.42cvss 6.4epss 0.00

    Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in…

  • CVE-2019-20925HigNov 24, 2020
    risk 0.42cvss 7.5epss 0.02

    An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to…

  • CVE-2018-20803MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions…

  • CVE-2020-7928MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions…

  • CVE-2019-2393MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13 and MongoDB Server…

  • CVE-2019-2392MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to overflow negative values. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9;…

  • CVE-2018-20805MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This issue affects MongoDB Server v4.0 versions prior to 4.0.5 and MongoDB Server v3.6 versions prior to 3.6.10.

  • CVE-2018-20804MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.

  • CVE-2018-20802MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects MongoDB Server v3.6 versions prior to 3.6.9 and MongoDB Server v4.0 versions prior to 4.0.3.

  • CVE-2020-7926MedNov 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB Server v4.4 versions prior to 4.4.1. Versions before 4.4 are not affected.

  • CVE-2020-7923MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.01

    A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2…

  • CVE-2020-7922MedApr 9, 2020
    risk 0.42cvss 6.4epss 0.01

    X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their…

  • CVE-2015-4411HigFeb 20, 2020
    risk 0.42cvss 7.5epss 0.06

    The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

  • CVE-2018-13863HigJul 10, 2018
    risk 0.42cvss 7.5epss 0.02

    The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long…

  • CVE-2026-13067MedJul 22, 2026
    risk 0.41cvss 6.3epss 0.00

    When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected…

  • CVE-2026-6915MedApr 29, 2026
    risk 0.41cvss 6.3epss 0.00

    An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. This could affect how authentication is performed for the impacted account.

  • CVE-2025-1692MedFeb 27, 2025
    risk 0.41cvss 6.3epss 0.00

    The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious…

  • CVE-2024-6376HigJul 1, 2024
    risk 0.39cvss 7.0epss 0.00

    MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2

  • CVE-2026-9100MedMay 20, 2026
    risk 0.38cvss 5.9epss 0.00

    The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or…

  • CVE-2026-6811MedMay 14, 2026
    risk 0.38cvss 5.9epss 0.00

    Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

  • CVE-2019-2388MedMay 13, 2020
    risk 0.38cvss 5.8epss 0.01

    In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1…

  • CVE-2025-12119MedNov 18, 2025
    risk 0.37cvss 6.8epss 0.00

    A mongoc_bulk_operation_t may read invalid memory if large options are passed.

  • CVE-2021-20329MedJun 10, 2021
    risk 0.37cvss 6.8epss 0.01

    Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO…

  • CVE-2026-19502MedAug 12, 2026
    risk 0.36cvss 5.5epss 0.00

    MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext…

  • CVE-2026-9751MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

  • CVE-2026-9735MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

  • CVE-2022-48282MedFeb 21, 2023
    risk 0.36cvss 6.6epss 0.01

    Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver…

  • CVE-2021-32039MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.00

    Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension…

  • CVE-2014-8180MedJun 6, 2017
    risk 0.36cvss 5.5epss 0.00

    MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.

  • CVE-2016-6494MedOct 3, 2016
    risk 0.36cvss 5.5epss 0.00

    The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.