Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-13060 $graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access CWE-863 6.5 Medium2026-07-22
CVE-2026-13061 Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage CWE-863 4.3 Medium2026-07-22
CVE-2026-13062 MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters CWE-441 6.5 Medium2026-07-22
CVE-2026-13063 libmongocrypt Improper Input Validation Leading to Process Termination CWE-190 4.3 Medium2026-07-22
CVE-2026-13064 MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service CWE-407 6.5 Medium2026-07-22
CVE-2026-13065 MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination CWE-476 6.5 Medium2026-07-22
CVE-2026-13066 Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure CWE-843 6.5 Medium2026-07-22
CVE-2026-13067 tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket CWE-863 6.3 Medium2026-07-22
CVE-2026-13068 MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse CWE-863 4.2 Medium2026-07-22
CVE-2026-13069 Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion CWE-770 6.5 Medium2026-07-22
CVE-2026-13070 Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination CWE-476 5.3 Medium2026-07-22
CVE-2026-13071 Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termination CWE-416 6.5 Medium2026-07-22
CVE-2026-13072 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption CWE-122 8.1 High2026-07-22
CVE-2026-13073 MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination CWE-617 4.3 Medium2026-07-22
CVE-2026-13074 Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service CWE-770 5.3 Medium2026-07-22
CVE-2026-13075 $rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation CWE-770 6.5 Medium2026-07-22
CVE-2026-13076 Aggregation Framework Memory Exhaustion Leading to Process Termination CWE-770 6.5 Medium2026-07-22
CVE-2026-13077 Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data CWE-125 7.1 High2026-07-22
CVE-2026-13078 Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader CWE-862 7.7 High2026-07-22
CVE-2026-9740 Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow CWE-674 7.5 High2026-06-09
CVE-2026-9735 Keyfile contents are in MongoDB Server logs CWE-532 5.5 Medium2026-06-09
CVE-2026-9753 Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. CWE-1287 8.1 High2026-06-09
CVE-2026-9752 GeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation CWE-476 6.5 Medium2026-06-09
CVE-2026-9751 Sensitive data could be written to mongod.log CWE-532 5.5 Medium2026-06-09
CVE-2026-9750 Metadata name collision on $-prefixed fields causes post-auth server crash CWE-617 6.5 Medium2026-06-09
CVE-2026-9749 Using MaxKey() may crash the server CWE-617 6.5 Medium2026-06-09
CVE-2026-9748 $_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input CWE-617 6.5 Medium2026-06-09
CVE-2026-9747 Crafted cross-shard merge aggregation crashes MongoDB Server CWE-617 6.5 Medium2026-06-09
CVE-2026-9746 Server crashes in case of the use of exchange CWE-617 6.5 Medium2026-06-09
CVE-2026-9743 Aggregation sub-pipeline null dereference may allow DoS via crafted getMore CWE-476 6.5 Medium2026-06-09

All 146 known CVE vulnerabilities affecting MongoDB server with full Chinese analysis, references, and POCs where available.