Mongodb Security Vulnerabilities (CVEs)
Track 37 security vulnerabilities affecting Mongodb products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
An authenticated MongoDB user can crash the database server by executing a query that targets a collection with an invalid compound wildcard index. Th...
Feb 10, 2026This MongoDB vulnerability allows authenticated users to bypass intended read-only restrictions on the 'filter' parameter in profile commands, potenti...
Feb 10, 2026This vulnerability in MongoDB allows connections from proxy ports to bypass connection counting, potentially causing server crashes when connection li...
Feb 10, 2026This vulnerability allows attackers to crash MongoDB servers by sending complex queries that trigger excessive memory usage in the query planner. All ...
Feb 10, 2026This vulnerability allows unauthenticated clients to read uninitialized heap memory from MongoDB servers by exploiting mismatched length fields in Zli...
Dec 19, 2025A post-authentication flaw in MongoDB's two-phase commit protocol for cross-shard transactions can cause logical data inconsistencies under specific, ...
Dec 9, 2025A privilege escalation vulnerability in MongoDB Server allows users with limited privileges to terminate queries executed by other users, causing deni...
Nov 25, 2025MongoDB Server may crash due to an invariant failure during batched delete operations when handling documents. The server incorrectly assumes multiple...
Nov 25, 2025This vulnerability in MongoDB Server allows oversized BSON documents to bypass initial size validation in time series processing, causing an assertion...
Nov 25, 2025This CVE describes a TLS certificate validation bypass vulnerability in MongoDB servers. On Windows and Apple systems, MongoDB may accept client certi...
Nov 25, 2025This vulnerability in MongoDB C driver allows reading invalid memory when large options are passed to mongoc_bulk_operation_t functions. This affects ...
Nov 18, 2025MongoDB's KMIP response parser accepts malformed packets that create invalid objects, causing read access violations when accessed. This affects Mongo...
Nov 3, 2025This vulnerability in MongoDB Rust Driver disables TLS certificate validation when tlsInsecure=False appears in connection strings, allowing man-in-th...
Oct 13, 2025An authorized MongoDB user can cause a denial of service by sending specially crafted $group queries with certain accumulator functions. This vulnerab...
Sep 5, 2025An improper handling of the lsid field in sharded queries can cause MongoDB routers to crash when this field is provided in contexts where it's not ap...
Sep 5, 2025MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, causing an invariant failure and server c...
Sep 5, 2025An authorized MongoDB user can cause a server crash by issuing queries containing duplicate _id fields, leading to denial of service. This affects Mon...
Jul 7, 2025This vulnerability allows unauthorized users to bypass MongoDB's authorization controls by exploiting a flaw in the $mergeCursors aggregation pipeline...
Jul 7, 2025MongoDB Server versions 8.0 prior to 8.0.10 have a memory management vulnerability where certain internal operations can cause excessive memory consum...
Jul 7, 2025An authenticated MongoDB user can trigger a use-after-free vulnerability by executing specific aggregation pipeline operations, causing server crashes...
Jun 26, 2025MongoDB Server is vulnerable to denial of service when processing specific date values in JSON input during OIDC authentication. An attacker can crash...
Jun 26, 2025This vulnerability allows improper authentication in MongoDB servers when TLS with CRL revocation checking is enabled on Linux systems. It affects Mon...
Apr 1, 2025A vulnerability in MongoDB's mongos query router allows unauthenticated attackers to send specially crafted wire protocol messages that cause the serv...
Apr 1, 2025A buffer overflow vulnerability in MongoDB's C driver library (libbson) allows attackers to cause segmentation faults and application crashes by creat...
Mar 18, 2025MongoDB Compass versions before 1.42.1 are vulnerable to local privilege escalation when a malicious file is placed in the C:\node_modules\ directory....
Feb 27, 2025MongoDB Shell (mongosh) versions before 2.3.0 are vulnerable to local privilege escalation when a malicious file is placed in C:\node_modules\. This a...
Feb 27, 2025This CVE describes a control character injection vulnerability in MongoDB Shell (mongosh) where an attacker controlling a MongoDB cluster can craft ma...
Feb 27, 2025This vulnerability allows attackers to inject malicious code into MongoDB Shell (mongosh) through clipboard manipulation. An attacker controlling the ...
Feb 27, 2025An authenticated MongoDB user can cause server crashes or read unauthorized memory contents by sending specially crafted requests with malformed BSON....
Nov 14, 2024MongoDB Server v6.0.3 contains a memory access vulnerability in internal aggregation stage processing when zero arguments are called. This could lead ...
Sep 10, 2024This vulnerability allows an attacker with host-level access on Linux systems to manipulate MongoDB server startup to load malicious shared libraries,...
Aug 27, 2024The bson_strfreev function in MongoDB's C driver library contains an integer overflow vulnerability that can cause memory corruption when freeing memo...
Jul 2, 2024MongoDB Compass versions before 1.42.2 have insufficient sandbox protection in the ejson shell parser used for connection handling, allowing potential...
Jul 1, 2024CVE-2024-3372 is an improper input validation vulnerability in MongoDB Server that allows pre-authentication attackers to send malformed metadata caus...
May 14, 2024This vulnerability allows authenticated MongoDB users to bypass IP whitelisting protection after administrative actions like role modifications. It af...
May 6, 2020A vulnerability in MongoDB's js-bson library versions 1.1.3 and earlier allows incorrect parsing of certain JSON inputs, leading to improper BSON seri...
Mar 31, 2020This MongoDB vulnerability allows authenticated users to maintain authorization sessions after their accounts are deleted, potentially gaining access ...
Aug 6, 2019Why Monitor Mongodb Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 37+ known vulnerabilities affecting Mongodb products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mongodb packages in under 60 seconds. No agents required - completely agentless scanning that works across Mongodb deployments.
Free vulnerability database: Access detailed information about every Mongodb CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Mongodb CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions