CVE-2026-4359Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB C++ Driver | Published03/17/2026 | SeverityLow |
|---|
CVE-2026-4358Memory safety issues in slot-based execution hash table spill | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published03/17/2026 | SeverityMedium |
|---|
CVE-2026-4148ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published03/17/2026 | SeverityHigh |
|---|
CVE-2026-4147Stack memory disclosure in filemd5 command | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published03/17/2026 | SeverityHigh |
|---|
CVE-2026-2303Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Go Driver | Published02/10/2026 | SeverityMedium |
|---|
CVE-2026-2302Unsafe Reflection in Mongoid::Criteria.from_hash | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Ruby Driver | Published02/10/2026 | SeverityMedium |
|---|
CVE-2026-25613An unsafe cast in the MongoDB query planner can result in a segmentation fault. | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-1849Mongod can run out of stack memory when expressions create deeply nested documents | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-1850An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-25609profile command may permit unauthorized configuration | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityMedium |
|---|
CVE-2026-25610Invalid $geoNear index hint may cause server crash | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-1848Connections received from the proxy port may not count towards total accepted connections | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-1847MongoDB Server may crash when inserting large documents | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-25612Internal ResourceId collision may affect unrelated collections | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2026-25611Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published02/10/2026 | SeverityHigh |
|---|
CVE-2025-11535MongoDB Connector for BI installation MSI leave ACLs unset on custom installation directories | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Connector for BI | Published10/08/2025 | SeverityHigh |
|---|
CVE-2025-10491MongoDB Windows installation MSI may leave ACLs unset on custom installation directories | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published09/15/2025 | SeverityHigh |
|---|
CVE-2025-10061Malformed $group Query May Cause MongoDB Server to Crash | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published09/05/2025 | SeverityMedium |
|---|
CVE-2025-10060MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published09/05/2025 | SeverityMedium |
|---|
CVE-2025-10059MongoDB Server router will crash when incorrect lsid is set on a sharded query | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published09/05/2025 | SeverityMedium |
|---|
CVE-2025-7259Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/07/2025 | SeverityMedium |
|---|
CVE-2025-6714Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/07/2025 | SeverityHigh |
|---|
CVE-2025-6713MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/07/2025 | SeverityHigh |
|---|
CVE-2025-6712MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/07/2025 | SeverityMedium |
|---|
CVE-2025-6711Incomplete Redaction of Sensitive Information in MongoDB Server Logs | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/07/2025 | SeverityMedium |
|---|
CVE-2025-6710Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published06/26/2025 | SeverityHigh |
|---|
CVE-2025-6709Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC Authentication | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published06/26/2025 | SeverityHigh |
|---|
CVE-2025-6707Race condition in privilege cache invalidation cycle | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published06/26/2025 | SeverityMedium |
|---|
CVE-2025-6706Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published06/26/2025 | SeverityMedium |
|---|
CVE-2025-3085MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published04/01/2025 | SeverityHigh |
|---|
CVE-2025-3084MongoDB Server may crash due to improper validation of explain command | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published04/01/2025 | SeverityMedium |
|---|
CVE-2025-3083Malformed MongoDB wire protocol messages may cause mongos to crash | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published04/01/2025 | SeverityHigh |
|---|
CVE-2025-3082User may override a view's collation and gain unauthorized access to underlying data | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published04/01/2025 | SeverityLow |
|---|
CVE-2025-0755MongoDB C Driver bson library may be susceptible to buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productL libbson | Published03/18/2025 | SeverityHigh |
|---|
CVE-2025-1756MongoDB Shell may be susceptible to local privilege escalation in Windows | Exploitation statusNot known exploited | FixYes | Affected productM mongosh | Published02/27/2025 | SeverityHigh |
|---|
CVE-2025-1755MongoDB Compass may be susceptible to local privilege escalation in Windows | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Compass | Published02/27/2025 | SeverityHigh |
|---|
CVE-2025-1693MongoDB Shell may be susceptible to control character Injection via shell output | Exploitation statusNot known exploited | FixYes | Affected productM mongosh | Published02/27/2025 | SeverityLow |
|---|
CVE-2025-1692MongoDB Shell may be susceptible to control character injection via pasting | Exploitation statusNot known exploited | FixYes | Affected productM mongosh | Published02/27/2025 | SeverityMedium |
|---|
CVE-2025-1691MongoDB Shell may be susceptible to Control Character Injection via autocomplete | Exploitation statusNot known exploited | FixYes | Affected productM mongosh | Published02/27/2025 | SeverityHigh |
|---|
CVE-2024-10921Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published11/14/2024 | SeverityMedium |
|---|
CVE-2024-8013CSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelines | Exploitation statusNot known exploited | FixYes | Affected productM mongocryptd | Published10/28/2024 | SeverityLow |
|---|
CVE-2024-8305MongoDB Server secondaries may crash due to forced index constraints | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published10/21/2024 | SeverityMedium |
|---|
CVE-2024-8654MongoDB Server may access non-initialized region of memory leading to unexpected behaviour | Exploitation statusNot known exploited | FixNot confirmed | Affected productM MongoDB Server | Published09/10/2024 | SeverityMedium |
|---|
CVE-2024-8207MongoDB Server binaries may load potentially insecure shared libraries from specific relative paths | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published08/27/2024 | SeverityMedium |
|---|
CVE-2024-6384Backup files may be downloaded by underprivileged users in MongoDB Enterprise Server | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published08/13/2024 | SeverityMedium |
|---|
CVE-2024-7553Accessing Untrusted Directory May Allow Local Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published08/07/2024 | SeverityHigh |
|---|
CVE-2024-6383MongoDB C Driver bson_string_append may be vulnerable to a buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productL libbson | Published07/03/2024 | SeverityMedium |
|---|
CVE-2024-6382Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands. | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Rust Driver | Published07/02/2024 | SeverityMedium |
|---|
CVE-2024-6381MongoDB C Driver bson_strfreev may be susceptible to integer overflow | Exploitation statusNot known exploited | FixYes | Affected productL libbson | Published07/02/2024 | SeverityMedium |
|---|
CVE-2024-6376ejson shell parser in MongoDB Compass maybe bypassed | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Compass | Published07/01/2024 | SeverityHigh |
|---|
CVE-2024-6375Missing authorization check may lead to shard key refinement | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published07/01/2024 | SeverityMedium |
|---|
CVE-2024-5629Out-of-bounds read in bson module of PyMongo | Exploitation statusNot known exploited | FixYes | Affected productP PyMongo | Published06/05/2024 | SeverityMedium |
|---|
CVE-2024-3374MongoDB Server (mongod) may crash when generating ftdc | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published05/14/2024 | SeverityMedium |
|---|
CVE-2024-3372MongoDB Server may have unexpected application behaviour due to invalid BSON | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published05/14/2024 | SeverityHigh |
|---|
CVE-2024-3371Insufficient validation of external input in Compass may enable MITM attacks | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Compass | Published04/24/2024 | SeverityHigh |
|---|
CVE-2024-1351MongoDB Server may allow successful untrusted connection | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published03/07/2024 | SeverityHigh |
|---|
CVE-2023-0437MongoDB client C Driver may infinitely loop when validating certain BSON input data | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB C++ Driver | Published01/12/2024 | SeverityMedium |
|---|
CVE-2023-0436Secret logging may occur in debug mode of Atlas Operator | Exploitation statusNot confirmed | FixYes | Affected productM MongoDB Atlas Kubernetes Operator | Published11/07/2023 | SeverityMedium |
|---|
CVE-2021-32050Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB C++ Driver | Published08/29/2023 | SeverityMedium |
|---|
CVE-2023-1409Certificate validation issue in MongoDB Server running on Windows or macOS | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB Server | Published08/23/2023 | SeverityMedium |
|---|
CVE-2022-48282Deserializing compromised object with MongoDB .NET/C# Driver may cause remote code execution | Exploitation statusNot known exploited | FixYes | Affected productM MongoDB .NET/C# Driver | Published02/21/2023 | SeverityMedium |
|---|