Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MongoDB Inc — Vulnerabilities & Security Advisories 61

Browse all 61 CVE security advisories affecting MongoDB Inc. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MongoDB Inc. develops a popular document-oriented NoSQL database designed for high-volume data storage and flexible schema management. Historically, its codebase has been associated with sixty-one recorded Common Vulnerabilities and Exposures, predominantly involving improper input validation and authentication bypasses. These flaws frequently enable remote code execution or unauthorized access, reflecting challenges in securing complex query parsers and network interfaces. While the company maintains a security response team and provides regular patches, the sheer volume of disclosed issues highlights the inherent risks in widely deployed, feature-rich database engines. Notable incidents have included critical flaws allowing unauthenticated data exfiltration, underscoring the necessity for rigorous configuration hardening. Organizations utilizing this platform must prioritize strict access controls and timely updates to mitigate the persistent threat landscape associated with its extensive attack surface and widespread adoption in enterprise environments.

Found 40 results / 61 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-4358 Memory safety issues in slot-based execution hash table spill — MongoDB Server CWE-415 6.4 Medium 2026-03-17
CVE-2026-4148 ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators — MongoDB Server CWE-416 8.8 High 2026-03-17
CVE-2026-4147 Stack memory disclosure in filemd5 command — MongoDB Server CWE-457 6.5 Medium 2026-03-17
CVE-2026-25613 An unsafe cast in the MongoDB query planner can result in a segmentation fault. — MongoDB Server CWE-704 6.5 Medium 2026-02-10
CVE-2026-1849 Mongod can run out of stack memory when expressions create deeply nested documents — MongoDB Server CWE-674 6.5 Medium 2026-02-10
CVE-2026-1850 An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification — MongoDB Server CWE-770 6.5 Medium 2026-02-10
CVE-2026-25609 profile command may permit unauthorized configuration — MongoDB Server CWE-862 5.4 Medium 2026-02-10
CVE-2026-25610 Invalid $geoNear index hint may cause server crash — MongoDB Server CWE-617 6.5 Medium 2026-02-10
CVE-2026-1848 Connections received from the proxy port may not count towards total accepted connections — MongoDB Server CWE-770 7.5 High 2026-02-10
CVE-2026-1847 MongoDB Server may crash when inserting large documents — MongoDB Server CWE-770 6.5 Medium 2026-02-10
CVE-2026-25612 Internal ResourceId collision may affect unrelated collections — MongoDB Server CWE-412 6.5 Medium 2026-02-10
CVE-2026-25611 Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server — MongoDB Server CWE-405 7.5 High 2026-02-10
CVE-2025-10491 MongoDB Windows installation MSI may leave ACLs unset on custom installation directories — MongoDB Server CWE-284 7.8 High 2025-09-15
CVE-2025-10061 Malformed $group Query May Cause MongoDB Server to Crash — MongoDB Server CWE-20 6.5 Medium 2025-09-05
CVE-2025-10060 MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation — MongoDB Server CWE-672 6.5 Medium 2025-09-05
CVE-2025-10059 MongoDB Server router will crash when incorrect lsid is set on a sharded query — MongoDB Server CWE-732 6.5 Medium 2025-09-05
CVE-2025-7259 Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash — MongoDB Server CWE-843 6.5 Medium 2025-07-07
CVE-2025-6714 Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections — MongoDB Server CWE-834 7.5 High 2025-07-07
CVE-2025-6713 MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage — MongoDB Server CWE-285 7.7 High 2025-07-07
CVE-2025-6712 MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation — MongoDB Server CWE-400 6.5 Medium 2025-07-07
CVE-2025-6711 Incomplete Redaction of Sensitive Information in MongoDB Server Logs — MongoDB Server CWE-532 4.4 Medium 2025-07-07
CVE-2025-6710 Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB — MongoDB Server CWE-674 7.5 High 2025-06-26
CVE-2025-6709 Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC Authentication — MongoDB Server CWE-20 7.5 High 2025-06-26
CVE-2025-6707 Race condition in privilege cache invalidation cycle — MongoDB Server CWE-863 4.2 Medium 2025-06-26
CVE-2025-6706 Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server — MongoDB Server CWE-416 5.0 Medium 2025-06-26
CVE-2025-3085 MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked — MongoDB Server CWE-299 8.1 High 2025-04-01
CVE-2025-3084 MongoDB Server may crash due to improper validation of explain command — MongoDB Server CWE-703 6.5 Medium 2025-04-01
CVE-2025-3083 Malformed MongoDB wire protocol messages may cause mongos to crash — MongoDB Server CWE-248 7.5 High 2025-04-01
CVE-2025-3082 User may override a view's collation and gain unauthorized access to underlying data — MongoDB Server CWE-284 3.1 Low 2025-04-01
CVE-2024-10921 Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server — MongoDB Server CWE-158 6.8 Medium 2024-11-14

This page lists every published CVE security advisory associated with MongoDB Inc. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.