Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Mongodb

62 known vulnerabilities

13
HIGH
47
MEDIUM
2
LOW

Top Products

mongodb 59 c driver 3
62 CVEs · Page 1/2
7.7
CVE-2026-13078

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered

7.1
CVE-2026-13077

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read

6.5
CVE-2026-13076

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p

6.5
CVE-2026-13075

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th

5.3
CVE-2026-13074

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati

4.3
CVE-2026-13073

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte

8.1
CVE-2026-13072

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du

6.5
CVE-2026-13071

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express

5.3
CVE-2026-13070

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons

6.5
CVE-2026-13069

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c

4.2
CVE-2026-13068

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac

6.3
CVE-2026-13067

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v

6.5
CVE-2026-13066

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i

6.5
CVE-2026-13065

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator

6.5
CVE-2026-13064

Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in

4.3
CVE-2026-13063

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem

6.5
CVE-2026-13062

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal

4.3
CVE-2026-13061

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi

6.5
CVE-2026-13060

An authenticated user with limited read privileges may be able to access documents from collections they are not authori

8.1
CVE-2026-13059

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role

6.5
CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf

5.3
CVE-2026-13057

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In

6.5
CVE-2026-13056

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object

6.5
CVE-2026-13055

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)

8.8
CVE-2026-11933

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t

6.5
CVE-2026-9754

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is

8.1
CVE-2026-9753

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed

6.5
CVE-2026-9752

An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO

5.5
CVE-2026-9751

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon

6.5
CVE-2026-9750

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe

6.5
CVE-2026-9749

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran

6.5
CVE-2026-9748

The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st

6.5
CVE-2026-9747

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

6.5
CVE-2026-9746

When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which

6.5
CVE-2026-9743

In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines

7.5
CVE-2026-9742

When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th

6.5
CVE-2026-9741

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F

7.5
CVE-2026-9740

A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by

5.5
CVE-2026-9735

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W

7.5
CVE-2026-8336

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in

4.3
CVE-2026-8202

Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r

6.4
CVE-2026-8201

A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie

2.7
CVE-2026-8200

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc

6.5
CVE-2026-8199

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny

8.8
CVE-2026-8053

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv

6.5
CVE-2026-8063

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When

7.8
CVE-2026-6691

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling

6.3
CVE-2026-6915

An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen

6.5
CVE-2026-6914

Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD

4.3
CVE-2026-6231

The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul

Frequently Asked Questions

How many CVEs affect Mongodb?

Mongodb has 62 CVE records in our database, including 0 critical and 13 high severity vulnerabilities.

What are the most severe Mongodb vulnerabilities?

Mongodb has 0 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Mongodb vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mongodb products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Mongodb Vulnerabilities

CyberStrike scans your infrastructure for Mongodb vulnerabilities and provides real-time remediation guidance.

Get Started