MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server存在安全漏洞,该漏洞源于使用内部$exchange阶段配置键范围分区和保序传递时,单个键范围填满交换缓冲区但未更新内部高水位标记,可能导致服务器崩溃或返回错误结果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | MongoDB Server | 8.3.0< 8.3.3 |
affected |
8.2.0< 8.2.10 |
affected | ||
8.0.0< 8.0.24 |
affected | ||
7.0.0< 7.0.35 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | MongoDB Server | 8.3.0 ~ 8.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9753 | 8.1 HIGH | Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. |
| CVE-2026-9740 | 7.5 HIGH | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow |
| CVE-2026-9742 | 7.5 HIGH | Authenticate command with specific mechanism parameter can trigger server crash |
| CVE-2026-9750 | 6.5 MEDIUM | Metadata name collision on $-prefixed fields causes post-auth server crash |
| CVE-2026-9748 | 6.5 MEDIUM | $_internalConvertBucketIndexStats may crash the mongod server when working on no timeserie |
| CVE-2026-9747 | 6.5 MEDIUM | Crafted cross-shard merge aggregation crashes MongoDB Server |
| CVE-2026-9741 | 6.5 MEDIUM | Client side encryption fails to encrypt values in a $vectorSearch |
| CVE-2026-9752 | 6.5 MEDIUM | GeometryCollection with strict-winding polygon causes server crash during 2dsphere index k |
| CVE-2026-9746 | 6.5 MEDIUM | Server crashes in case of the use of exchange |
| CVE-2026-9743 | 6.5 MEDIUM | Aggregation sub-pipeline null dereference may allow DoS via crafted getMore |
| CVE-2026-9754 | 6.5 MEDIUM | Stack memory disclosure in filemd5 command |
| CVE-2026-9751 | 5.5 MEDIUM | Sensitive data could be written to mongod.log |
| CVE-2026-9735 | 5.5 MEDIUM | Keyfile contents are in MongoDB Server logs |
No comments yet