Mongoosejs
Products
1- Mongoose9 CVEsnpm
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2564 | Cri | 0.59 | 9.8 | 0.33 | Jul 28, 2022 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | ||
| CVE-2023-3696 | Cri | 0.57 | 9.8 | 0.01 | Jul 17, 2023 | Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4. | ||
| CVE-2025-23061 | Cri | 0.52 | 9.0 | 0.07 | Jan 15, 2025 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. | ||
| CVE-2024-53900 | Cri | 0.52 | 9.1 | 0.04 | Dec 2, 2024 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. | ||
| CVE-2019-17426 | Cri | 0.52 | 9.1 | 0.02 | Oct 10, 2019 | Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's… | ||
| CVE-2026-42334 | Hig | 0.49 | 7.5 | 0.00 | May 14, 2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled,… | ||
| CVE-2018-10945 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2018 | The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function. | ||
| CVE-2009-1354 | 0.03 | — | 0.02 | Apr 21, 2009 | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |||
| CVE-2009-4530 | 0.00 | — | 0.01 | Dec 31, 2009 | Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI. |
- risk 0.59cvss 9.8epss 0.33
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
- risk 0.57cvss 9.8epss 0.01
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
- risk 0.52cvss 9.0epss 0.07
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
- risk 0.52cvss 9.1epss 0.04
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
- risk 0.52cvss 9.1epss 0.02
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's…
- risk 0.49cvss 7.5epss 0.00
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled,…
- risk 0.49cvss 7.5epss 0.01
The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.
- CVE-2009-1354Apr 21, 2009risk 0.03cvss —epss 0.02
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
- CVE-2009-4530Dec 31, 2009risk 0.00cvss —epss 0.01
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.