Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE ID Title CVSS Severity Published
CVE-2025-13507 Time-series operations may cause internal BSON size limit to be exceed CWE-1284 6.5 Medium 2025-11-25
CVE-2025-12657 Malformed KMIP response may result in access violation CWE-754 5.0 Medium 2025-11-03
CVE-2025-10491 MongoDB Windows installation MSI may leave ACLs unset on custom installation directories CWE-284 7.8 High 2025-09-15
CVE-2025-10061 Malformed $group Query May Cause MongoDB Server to Crash CWE-20 6.5 Medium 2025-09-05
CVE-2025-10060 MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation CWE-672 6.5 Medium 2025-09-05
CVE-2025-10059 MongoDB Server router will crash when incorrect lsid is set on a sharded query CWE-732 6.5 Medium 2025-09-05
CVE-2025-7259 Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash CWE-843 6.5 Medium 2025-07-07
CVE-2025-6714 Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections CWE-834 7.5 High 2025-07-07
CVE-2025-6713 MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage CWE-285 7.7 High 2025-07-07
CVE-2025-6712 MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation CWE-400 6.5 Medium 2025-07-07
CVE-2025-6711 Incomplete Redaction of Sensitive Information in MongoDB Server Logs CWE-532 4.4 Medium 2025-07-07
CVE-2025-6710 Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB CWE-674 7.5 High 2025-06-26
CVE-2025-6709 Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC Authentication CWE-20 7.5 High 2025-06-26
CVE-2025-6707 Race condition in privilege cache invalidation cycle CWE-863 4.2 Medium 2025-06-26
CVE-2025-6706 Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server CWE-416 5.0 Medium 2025-06-26
CVE-2025-3085 MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked CWE-299 8.1 High 2025-04-01
CVE-2025-3084 MongoDB Server may crash due to improper validation of explain command CWE-703 6.5 Medium 2025-04-01
CVE-2025-3083 Malformed MongoDB wire protocol messages may cause mongos to crash CWE-248 7.5 High 2025-04-01
CVE-2025-3082 User may override a view's collation and gain unauthorized access to underlying data CWE-284 3.1 Low 2025-04-01
CVE-2024-10921 Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server CWE-158 6.8 Medium 2024-11-14
CVE-2024-8305 MongoDB Server secondaries may crash due to forced index constraints CWE-1288 6.5 Medium 2024-10-21
CVE-2024-8654 MongoDB Server may access non-initialized region of memory leading to unexpected behaviour CWE-908 5.0 Medium 2024-09-10
CVE-2024-8207 MongoDB Server binaries may load potentially insecure shared libraries from specific relative paths CWE-114 6.4 Medium 2024-08-27
CVE-2024-6384 Backup files may be downloaded by underprivileged users in MongoDB Enterprise Server CWE-285 5.3 Medium 2024-08-13
CVE-2024-7553 Accessing Untrusted Directory May Allow Local Privilege Escalation CWE-284 7.3 High 2024-08-07
CVE-2024-6375 Missing authorization check may lead to shard key refinement CWE-285 5.4 Medium 2024-07-01
CVE-2024-3374 MongoDB Server (mongod) may crash when generating ftdc CWE-617 5.3 Medium 2024-05-14
CVE-2024-3372 MongoDB Server may have unexpected application behaviour due to invalid BSON CWE-20 7.5 High 2024-05-14
CVE-2024-1351 MongoDB Server may allow successful untrusted connection CWE-295 8.8 High 2024-03-07
CVE-2023-1409 Certificate validation issue in MongoDB Server running on Windows or macOS CWE-295 5.3 Medium 2023-08-23

All 146 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.