Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE ID Title CVSS Severity Published
CVE-2026-9742 Authenticate command with specific mechanism parameter can trigger server crash CWE-1287 7.5 High 2026-06-09
CVE-2026-9741 Client side encryption fails to encrypt values in a $vectorSearch CWE-319 6.5 Medium 2026-06-09
CVE-2026-8843 Calling createIndex with certain index types can crash mongod CWE-617 6.5 Medium 2026-05-18
CVE-2026-8202 Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators CWE-770 4.3 Medium 2026-05-13
CVE-2026-8336 Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands CWE-416 7.5 High 2026-05-13
CVE-2026-8201 Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields CWE-416 6.4 Medium 2026-05-13
CVE-2026-8200 Schema validation log messages may not redact user data CWE-532 2.7 Low 2026-05-13
CVE-2026-8199 Post-auth memory exhaustion via bitwise match expressions CWE-1325 6.5 Medium 2026-05-13
CVE-2026-8053 FlatBSON Duplicate Field Index Drift CWE-787 8.8 High 2026-05-12
CVE-2026-8063 Post-auth null pointer dereference when aggregating against a view with empty search pipeline CWE-476 6.5 Medium 2026-05-07
CVE-2026-6915 Flaw in the updateUser Command May Allow Unauthorized Configuration Change CWE-1284 6.3 Medium 2026-04-29
CVE-2026-6914 MD5 checksum creation may cause availability loss CWE-191 6.5 Medium 2026-04-29
CVE-2026-5170 Users could trigger a crash of mongod primaries during promotion to sharded CWE-617 5.3 Medium 2026-03-30
CVE-2026-4358 Memory safety issues in slot-based execution hash table spill CWE-415 6.4 Medium 2026-03-17
CVE-2026-4148 ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators CWE-416 8.8 High 2026-03-17
CVE-2026-4147 Stack memory disclosure in filemd5 command CWE-457 6.5 Medium 2026-03-17
CVE-2026-25613 An unsafe cast in the MongoDB query planner can result in a segmentation fault. CWE-704 6.5 Medium 2026-02-10
CVE-2026-1849 Mongod can run out of stack memory when expressions create deeply nested documents CWE-674 6.5 Medium 2026-02-10
CVE-2026-1850 An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification CWE-770 6.5 Medium 2026-02-10
CVE-2026-25609 profile command may permit unauthorized configuration CWE-862 5.4 Medium 2026-02-10
CVE-2026-25610 Invalid $geoNear index hint may cause server crash CWE-617 6.5 Medium 2026-02-10
CVE-2026-1848 Connections received from the proxy port may not count towards total accepted connections CWE-770 7.5 High 2026-02-10
CVE-2026-1847 MongoDB Server may crash when inserting large documents CWE-770 6.5 Medium 2026-02-10
CVE-2026-25612 Internal ResourceId collision may affect unrelated collections CWE-412 6.5 Medium 2026-02-10
CVE-2026-25611 Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server CWE-405 7.5 High 2026-02-10
CVE-2025-14847 Zlib compressed protocol header length confusion may allow memory read CWE-130 7.5 High 2025-12-19
CVE-2025-14345 Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server CWE-667 4.2 Medium 2025-12-09
CVE-2025-13644 MongoDB may be susceptible to Invariant Failure due to batched delete CWE-617 6.5 Medium 2025-11-25
CVE-2025-13643 MongoDB Server may allow queries to be terminated by unauthorized users CWE-862 3.1 Low 2025-11-25
CVE-2025-12893 Improper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Extended Key Usage Fields in MongoDB Server CWE-295 4.2 Medium 2025-11-25

All 146 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.