📦 Mongodb

by Mongodb

🔍 What is Mongodb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-1848

HIGH CVSS 7.5 Feb 10, 2026

This vulnerability in MongoDB allows connections from proxy ports to bypass connection counting, potentially causing server crashes when connection limits are exceeded. It affects MongoDB servers with...

CVE-2025-14847

HIGH CVSS 7.5 Dec 19, 2025

This vulnerability allows unauthenticated clients to read uninitialized heap memory from MongoDB servers by exploiting mismatched length fields in Zlib compressed protocol headers. This could leak sen...

CVE-2025-6713

HIGH CVSS 7.7 Jul 7, 2025

This vulnerability allows unauthorized users to bypass MongoDB's authorization controls by exploiting a flaw in the $mergeCursors aggregation pipeline stage. Attackers can access data they shouldn't h...

CVE-2025-6709

HIGH CVSS 7.5 Jun 26, 2025

MongoDB Server is vulnerable to denial of service when processing specific date values in JSON input during OIDC authentication. An attacker can crash the server by sending a malicious payload, affect...

CVE-2025-3085

HIGH CVSS 8.1 Apr 1, 2025

This vulnerability allows improper authentication in MongoDB servers when TLS with CRL revocation checking is enabled on Linux systems. It affects MongoDB X509 authentication and intra-cluster authent...

CVE-2025-3083

HIGH CVSS 7.5 Apr 1, 2025

A vulnerability in MongoDB's mongos query router allows unauthenticated attackers to send specially crafted wire protocol messages that cause the service to crash during command validation. This affec...

CVE-2025-0755

HIGH CVSS 8.4 Mar 18, 2025

A buffer overflow vulnerability in MongoDB's C driver library (libbson) allows attackers to cause segmentation faults and application crashes by creating BSON documents exceeding maximum size limits. ...

CVE-2024-3372

HIGH CVSS 7.5 May 14, 2024

CVE-2024-3372 is an improper input validation vulnerability in MongoDB Server that allows pre-authentication attackers to send malformed metadata causing BSON serialization errors. This can lead to un...

CVE-2019-2386

HIGH CVSS 7.1 Aug 6, 2019

This MongoDB vulnerability allows authenticated users to maintain authorization sessions after their accounts are deleted, potentially gaining access to new accounts that reuse the same username. It a...

CVE-2026-25613

MEDIUM CVSS 6.5 Feb 10, 2026

An authenticated MongoDB user can crash the database server by executing a query that targets a collection with an invalid compound wildcard index. This affects MongoDB deployments where users have qu...

CVE-2026-25609

MEDIUM CVSS 5.4 Feb 10, 2026

This MongoDB vulnerability allows authenticated users to bypass intended read-only restrictions on the 'filter' parameter in profile commands, potentially modifying database behavior. It affects Mongo...

CVE-2026-1850

MEDIUM CVSS 6.5 Feb 10, 2026

This vulnerability allows attackers to crash MongoDB servers by sending complex queries that trigger excessive memory usage in the query planner. All MongoDB deployments using affected versions are vu...

CVE-2025-14345

MEDIUM CVSS 4.2 Dec 9, 2025

A post-authentication flaw in MongoDB's two-phase commit protocol for cross-shard transactions can cause logical data inconsistencies under specific, unpredictable conditions. This may lead to misinte...

CVE-2025-13644

MEDIUM CVSS 6.5 Nov 25, 2025

MongoDB Server may crash due to an invariant failure during batched delete operations when handling documents. The server incorrectly assumes multiple documents exist in a batch based on document size...

CVE-2025-13507

MEDIUM CVSS 6.5 Nov 25, 2025

This vulnerability in MongoDB Server allows oversized BSON documents to bypass initial size validation in time series processing, causing an assertion failure that terminates the server process. It af...

CVE-2025-12893

MEDIUM CVSS 4.2 Nov 25, 2025

This CVE describes a TLS certificate validation bypass vulnerability in MongoDB servers. On Windows and Apple systems, MongoDB may accept client certificates missing the required clientAuth extended k...

CVE-2025-12657

MEDIUM CVSS 5.0 Nov 3, 2025

MongoDB's KMIP response parser accepts malformed packets that create invalid objects, causing read access violations when accessed. This affects MongoDB instances using KMIP for key management. The vu...

CVE-2025-10061

MEDIUM CVSS 6.5 Sep 5, 2025

An authorized MongoDB user can cause a denial of service by sending specially crafted $group queries with certain accumulator functions. This vulnerability affects MongoDB Server versions 6.0 before 6...

CVE-2025-10059

MEDIUM CVSS 6.5 Sep 5, 2025

An improper handling of the lsid field in sharded queries can cause MongoDB routers to crash when this field is provided in contexts where it's not applicable. This affects MongoDB Server versions 6.0...

CVE-2025-10060

MEDIUM CVSS 6.5 Sep 5, 2025

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, causing an invariant failure and server crash during commit. This affects MongoDB Server v6...

CVE-2025-7259

MEDIUM CVSS 6.5 Jul 7, 2025

An authorized MongoDB user can cause a server crash by issuing queries containing duplicate _id fields, leading to denial of service. This affects MongoDB Server v8.1.0 specifically. Only authenticate...

CVE-2025-6712

MEDIUM CVSS 6.5 Jul 7, 2025

MongoDB Server versions 8.0 prior to 8.0.10 have a memory management vulnerability where certain internal operations can cause excessive memory consumption, potentially leading to server crashes and d...

CVE-2025-6706

MEDIUM CVSS 5.0 Jun 26, 2025

An authenticated MongoDB user can trigger a use-after-free vulnerability by executing specific aggregation pipeline operations, causing server crashes even without shutdown privileges. This affects Mo...

CVE-2024-10921

MEDIUM CVSS 6.8 Nov 14, 2024

An authenticated MongoDB user can cause server crashes or read unauthorized memory contents by sending specially crafted requests with malformed BSON. This affects MongoDB Server versions 5.0 before 5...

CVE-2024-8654

MEDIUM CVSS 5.0 Sep 10, 2024

MongoDB Server v6.0.3 contains a memory access vulnerability in internal aggregation stage processing when zero arguments are called. This could lead to crashes, data corruption, or potential informat...

CVE-2024-8207

MEDIUM CVSS 6.4 Aug 27, 2024

This vulnerability allows an attacker with host-level access on Linux systems to manipulate MongoDB server startup to load malicious shared libraries, potentially gaining full control over the MongoDB...

CVE-2020-7921

MEDIUM CVSS 4.6 May 6, 2020

This vulnerability allows authenticated MongoDB users to bypass IP whitelisting protection after administrative actions like role modifications. It affects MongoDB Server versions 3.6 prior to 3.6.18,...

CVE-2025-13643

LOW CVSS 3.1 Nov 25, 2025

A privilege escalation vulnerability in MongoDB Server allows users with limited privileges to terminate queries executed by other users, causing denial of service by preventing queries from completin...