Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2025-13507 Time-series operations may cause internal BSON size limit to be exceed CWE-1284 6.5 Medium2025-11-25
CVE-2025-12657 Malformed KMIP response may result in access violation CWE-754 5.0 Medium2025-11-03
CVE-2025-10491 MongoDB Windows installation MSI may leave ACLs unset on custom installation directories CWE-284 7.8 High2025-09-15
CVE-2025-10061 Malformed $group Query May Cause MongoDB Server to Crash CWE-20 6.5 Medium2025-09-05
CVE-2025-10060 MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation CWE-672 6.5 Medium2025-09-05
CVE-2025-10059 MongoDB Server router will crash when incorrect lsid is set on a sharded query CWE-732 6.5 Medium2025-09-05
CVE-2025-7259 Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash CWE-843 6.5 Medium2025-07-07
CVE-2025-6714 Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections CWE-834 7.5 High2025-07-07
CVE-2025-6713 MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage CWE-285 7.7 High2025-07-07
CVE-2025-6712 MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation CWE-400 6.5 Medium2025-07-07
CVE-2025-6711 Incomplete Redaction of Sensitive Information in MongoDB Server Logs CWE-532 4.4 Medium2025-07-07
CVE-2025-6710 Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB CWE-674 7.5 High2025-06-26
CVE-2025-6709 Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC Authentication CWE-20 7.5 High2025-06-26
CVE-2025-6707 Race condition in privilege cache invalidation cycle CWE-863 4.2 Medium2025-06-26
CVE-2025-6706 Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server CWE-416 5.0 Medium2025-06-26
CVE-2025-3085 MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked CWE-299 8.1 High2025-04-01
CVE-2025-3084 MongoDB Server may crash due to improper validation of explain command CWE-703 6.5 Medium2025-04-01
CVE-2025-3083 Malformed MongoDB wire protocol messages may cause mongos to crash CWE-248 7.5 High2025-04-01
CVE-2025-3082 User may override a view's collation and gain unauthorized access to underlying data CWE-284 3.1 Low2025-04-01
CVE-2024-10921 Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server CWE-158 6.8 Medium2024-11-14
CVE-2024-8305 MongoDB Server secondaries may crash due to forced index constraints CWE-1288 6.5 Medium2024-10-21
CVE-2024-8654 MongoDB Server may access non-initialized region of memory leading to unexpected behaviour CWE-908 5.0 Medium2024-09-10
CVE-2024-8207 MongoDB Server binaries may load potentially insecure shared libraries from specific relative paths CWE-114 6.4 Medium2024-08-27
CVE-2024-6384 Backup files may be downloaded by underprivileged users in MongoDB Enterprise Server CWE-285 5.3 Medium2024-08-13
CVE-2024-7553 Accessing Untrusted Directory May Allow Local Privilege Escalation CWE-284 7.3 High2024-08-07
CVE-2024-6375 Missing authorization check may lead to shard key refinement CWE-285 5.4 Medium2024-07-01
CVE-2024-3374 MongoDB Server (mongod) may crash when generating ftdc CWE-617 5.3 Medium2024-05-14
CVE-2024-3372 MongoDB Server may have unexpected application behaviour due to invalid BSON CWE-20 7.5 High2024-05-14
CVE-2024-1351 MongoDB Server may allow successful untrusted connection CWE-295 8.8 High2024-03-07
CVE-2023-1409 Certificate validation issue in MongoDB Server running on Windows or macOS CWE-295 5.3 Medium2023-08-23

All 146 known CVE vulnerabilities affecting MongoDB server with full Chinese analysis, references, and POCs where available.