Mongodb
62 known vulnerabilities
Top Products
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c
An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal
An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi
An authenticated user with limited read privileges may be able to access documents from collections they are not authori
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W
After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling
An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul
Frequently Asked Questions
How many CVEs affect Mongodb?
Mongodb has 62 CVE records in our database, including 0 critical and 13 high severity vulnerabilities.
What are the most severe Mongodb vulnerabilities?
Mongodb has 0 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mongodb vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mongodb products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mongodb Vulnerabilities
CyberStrike scans your infrastructure for Mongodb vulnerabilities and provides real-time remediation guidance.
Get Started