← Browse

Mongodb

70 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-75159 HIGH 8.2 Bi Connector — An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authen… 2026-08-27 CVE-2026-75573 MEDIUM 4.1 Bi Connector — In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the passwor… 2026-08-27 CVE-2026-81521 HIGH 7.1 Go Driver — The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containin… 2026-08-27 CVE-2026-81522 HIGH 8.6 C++ Driver — A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special charac… 2026-08-27 CVE-2026-81523 LOW 2 Libmongocrypt — A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller… 2026-08-27 CVE-2026-81524 MEDIUM 5.3 C Driver — A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name com… 2026-08-27 CVE-2026-81525 HIGH 8.6 Php Library — The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied nam… 2026-08-27 CVE-2026-81526 HIGH 7.1 Rust Driver — The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before e… 2026-08-27 CVE-2026-81527 MEDIUM 6.9 C# Driver — A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB… 2026-08-27 CVE-2026-81528 MEDIUM 5.3 C# Driver — A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent… 2026-08-27 CVE-2026-81529 HIGH 7.1 C# Driver — Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the… 2026-08-27 CVE-2026-81530 MEDIUM 6.8 C# Driver — A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-m… 2026-08-27 CVE-2026-18888 HIGH 7.1 Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the… 2026-08-12 CVE-2026-19001 CRITICAL 9.5 Bi Connector Odbc Driver — The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application s… 2026-08-12 CVE-2026-19002 HIGH 8.8 Bi Connector Odbc Driver — A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Drive… 2026-08-12 CVE-2026-19003 HIGH 8.4 Bi Connector Odbc Driver — A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC D… 2026-08-12 CVE-2026-19004 HIGH 8.8 Bi Connector Odbc Driver — An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing… 2026-08-12 CVE-2026-19502 MEDIUM 6.8 Schema Builder Cli — MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is … 2026-08-12 CVE-2026-19503 MEDIUM 6.3 Atlas Sql Odbc Driver — MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and t… 2026-08-12 CVE-2026-18687 HIGH 7.1 Mongodb Server — MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain re… 2026-08-11 CVE-2026-18688 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-boun… 2026-08-11 CVE-2026-18690 HIGH 7.2 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an… 2026-08-11 CVE-2026-18691 CRITICAL 9 Mongodb Server — An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access t… 2026-08-11 CVE-2026-18692 HIGH 7.7 Mongodb Server — An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with wr… 2026-08-11 CVE-2026-18693 HIGH 7.2 Mongodb Server — An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write p… 2026-08-11 CVE-2026-18694 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileg… 2026-08-11 CVE-2026-18695 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaF… 2026-08-11 CVE-2026-18696 HIGH 7 Mongodb Server — An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default priv… 2026-08-11 CVE-2026-18697 HIGH 8.7 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (rou… 2026-08-11 CVE-2026-18698 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an… 2026-08-11 CVE-2026-18699 MEDIUM 6 Mongodb Server — An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cau… 2026-08-11 CVE-2026-18700 MEDIUM 6 Mongodb Server — An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to … 2026-08-11 CVE-2026-18701 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause t… 2026-08-11 CVE-2026-18702 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modif… 2026-08-11 CVE-2026-18703 LOW 2.3 Mongodb Server — An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user accoun… 2026-08-11 CVE-2026-18704 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges… 2026-08-11 CVE-2026-18705 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to… 2026-08-11 CVE-2026-18706 HIGH 7.5 Mongodb Server — An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue ag… 2026-08-11 CVE-2026-18707 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to ca… 2026-08-11 CVE-2026-18708 MEDIUM 5.3 Mongodb Server — An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileg… 2026-08-11 CVE-2026-18709 MEDIUM 5.9 Mongodb Server — An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improper… 2026-08-11 CVE-2026-18710 HIGH 8.2 Mongodb Driver — A MongoDB driver component could write sensitive configuration information, including a credential used for ou… 2026-08-11 CVE-2026-18711 HIGH 7.1 Mongodb Server — An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write priv… 2026-08-11 CVE-2026-18712 HIGH 7.2 Mongodb Server — An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user wit… 2026-08-11 CVE-2026-13055 HIGH 7.1 Mongodb Server — The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB serve… 2026-07-22 CVE-2026-13056 HIGH 7.1 Mongodb Server — Using expressions that generate large arrays it is possible to craft a query that creates very large intermedi… 2026-07-22 CVE-2026-13057 MEDIUM 6 Mongodb Server — An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access contr… 2026-07-22 CVE-2026-13058 HIGH 7.1 Mongodb Server — An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by send… 2026-07-22 CVE-2026-13059 HIGH 8.6 Mongodb Server — An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protect… 2026-07-22 CVE-2026-13060 HIGH 7.1 Mongodb Server — An authenticated user with limited read privileges may be able to access documents from collections they are n… 2026-07-22 CVE-2026-13061 MEDIUM 5.3 Mongodb Server — An authenticated user may be able to view session metadata belonging to other users on the system through the … 2026-07-22 CVE-2026-13062 HIGH 7.1 Mongodb Server — An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify… 2026-07-22 CVE-2026-13063 MEDIUM 5.3 Mongodb Server — An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an … 2026-07-22 CVE-2026-13064 HIGH 7.1 Mongodb Server — Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consu… 2026-07-22 CVE-2026-13065 HIGH 7.1 Mongodb Server — A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window functio… 2026-07-22 CVE-2026-13066 HIGH 7.1 Mongodb Server — Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine ca… 2026-07-22 CVE-2026-13067 HIGH 7.2 Mongodb Server — When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates ma… 2026-07-22 CVE-2026-13068 LOW 2.3 Mongodb Server — An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to te… 2026-07-22 CVE-2026-13069 HIGH 7.1 Mongodb Server — An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by s… 2026-07-22 CVE-2026-13070 MEDIUM 6 Mongodb Server — A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OC… 2026-07-22 CVE-2026-13071 HIGH 7.1 Mongodb Server — An authenticated user with read access can cause the mongod process to be terminated through certain aggregati… 2026-07-22 CVE-2026-13072 CRITICAL 9.2 Mongodb Server — When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BS… 2026-07-22 CVE-2026-13073 MEDIUM 5.3 Mongodb Server — An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuin… 2026-07-22 CVE-2026-13074 MEDIUM 6.9 Mongodb Server — An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific… 2026-07-22 CVE-2026-13075 HIGH 7.1 Mongodb Server — An authenticated user can cause the mongod process to be terminated by the operating system under memory press… 2026-07-22 CVE-2026-13076 HIGH 7.1 Mongodb Server — An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pre… 2026-07-22 CVE-2026-13077 HIGH 7.1 Mongodb Server — A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds… 2026-07-22 CVE-2026-13078 MEDIUM 6.3 Mongodb Server — A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally … 2026-07-22 CVE-2026-14881 HIGH 8.4 Mongodb Compass — When importing connections in Compass it is possible to override some connection options that are otherwise ca… 2026-07-22 CVE-2026-9737 HIGH 7.1 Mongodb Server — During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly ha… 2026-07-22