Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MongoDB Inc. — Vulnerabilities & Security Advisories 67

Browse all 67 CVE security advisories affecting MongoDB Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MongoDB Inc. develops a popular document-oriented NoSQL database designed for high-volume data storage and flexible schema management. With fifty recorded Common Vulnerabilities and Exposures (CVEs), the platform has historically faced issues ranging from remote code execution and cross-site scripting to privilege escalation flaws. These vulnerabilities often stem from improper input validation, authentication bypasses, or insecure default configurations in earlier releases. Notable incidents include critical flaws allowing unauthenticated access to administrative interfaces, highlighting risks associated with default settings in production environments. The company actively addresses these concerns through regular security patches and updates, emphasizing the importance of proper configuration and timely maintenance. While the software remains widely adopted for its scalability, the frequency of CVEs underscores the necessity for rigorous security hygiene and continuous monitoring to mitigate potential exploitation vectors in enterprise deployments.

CVE ID Title CVSS Severity Published
CVE-2026-93759 Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist — Mongoid CWE-94 8.6 High 2026-09-18
CVE-2026-93760 NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard — Mongoid CWE-943 8.2 High 2026-09-18
CVE-2026-93761 Denial of service via unbounded regex matching in Mongoid's in-memory query matcher — Mongoid CWE-1333 7.5 High 2026-09-18
CVE-2026-93762 Data deletion and attribute disclosure via field-name method injection in in-memory queries — Mongoid CWE-470 9.8 Critical 2026-09-18
CVE-2026-93763 Silent plaintext persistence via unresolved callable database name in encryption schema map — Mongoid CWE-312 6.5 Medium 2026-09-18
CVE-2026-93764 Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation — Mongoid CWE-312 6.5 Medium 2026-09-18
CVE-2026-93765 Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation — Mongoid CWE-470 9.1 Critical 2026-09-18
CVE-2026-93758 Cross-principal document update, theft, and deletion via unvalidated id in nested attributes — Mongoid CWE-639 8.1 High 2026-09-18
CVE-2026-93395 Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() — C Driver CWE-191 5.3 Medium 2026-09-17
CVE-2026-93394 libmongoc SCRAM client nonce-validation bypass — C Driver CWE-303 3.7 Low 2026-09-17
CVE-2026-93393 Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream — C Driver CWE-787 8.1 High 2026-09-17
CVE-2026-92757 Malformed connection string may disable field level encryption — MongoDB Entity Framework Core Provider CWE-311 5.5 Medium 2026-09-17
CVE-2026-92758 Logs may collect sensitive information — MongoDB Entity Framework Core Provider CWE-532 5.5 Medium 2026-09-17
CVE-2026-92756 Combining encryption settings may disable encryption — MongoDB Entity Framework Core Provider CWE-311 5.5 Medium 2026-09-17
CVE-2026-6811 PHP Stack Exhaustion — PHP Driver CWE-674 5.9 Medium 2026-05-14
CVE-2026-8063 Post-auth null pointer dereference when aggregating against a view with empty search pipeline — MongoDB Server CWE-476 6.5 Medium 2026-05-07
CVE-2026-6691 MongoDB C Driver Cyrus SASL Canonicalization Buffer Overflow — MongoDB C Driver CWE-120 7.8 High 2026-05-06
CVE-2026-6231 bson_validate may skip validation when processing certain inputs — C Driver CWE-20 4.3 Medium 2026-04-13
CVE-2025-14847 Zlib compressed protocol header length confusion may allow memory read — MongoDB Server CWE-130 7.5 High 2025-12-19
CVE-2025-14345 Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server — MongoDB Server CWE-667 4.2 Medium 2025-12-09
CVE-2025-13644 MongoDB may be susceptible to Invariant Failure due to batched delete — MongoDB Server CWE-617 6.5 Medium 2025-11-25
CVE-2025-13643 MongoDB Server may allow queries to be terminated by unauthorized users — MongoDB Server CWE-862 3.1 Low 2025-11-25
CVE-2025-12893 Improper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Extended Key Usage Fields in MongoDB Server — MongoDB Server CWE-295 4.2 Medium 2025-11-25
CVE-2025-13507 Time-series operations may cause internal BSON size limit to be exceed — MongoDB Server CWE-1284 6.5 Medium 2025-11-25
CVE-2025-12657 Malformed KMIP response may result in access violation — MongoDB Server CWE-754 5.0 Medium 2025-11-03
CVE-2025-11979 Use-after-free in the MongoDB server query planner may lead to crash or undefined behavior — Server CWE-416 5.3 Medium 2025-10-20
CVE-2023-4009 Privilege Escalation for Project Owner and Project User Admin Roles in Ops Manager — MongoDB Ops Manager CWE-648 7.2 High 2023-08-08
CVE-2023-0342 MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive — MongoDB Ops Manager CWE-497 3.1 Low 2023-06-09
CVE-2022-24272 MongoDB Server (mongod) may crash in response to unexpected requests — MongoDB Server CWE-617 6.5 Medium 2022-04-21
CVE-2021-32040 Large aggregation pipelines with a specific stage can crash mongod under default configuration — MongoDB Server CWE-121 6.5 Medium 2022-04-12

This page lists every published CVE security advisory associated with MongoDB Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.