MongoDB / Mongodb Server
171 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-89099 | Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption | HIGH | 7.7 | Sep 11, 2026 |
| CVE-2026-82076 | Integer Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB Server | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82075 | Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-82074 | Incorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection Data | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82073 | Improper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas Search | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82071 | Insufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds Write | HIGH | 7.2 | Sep 8, 2026 |
| CVE-2026-82070 | Insufficiently Protected Credentials in MongoDB Server Diagnostic Reporting Interface | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82069 | Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router | MEDIUM | 5.1 | Sep 8, 2026 |
| CVE-2026-82068 | Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82067 | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup | CRITICAL | 9.2 | Sep 8, 2026 |
| CVE-2026-82066 | Heap Out-of-Bounds Read in MongoDB Server Query Planning Component | MEDIUM | 5.3 | Sep 8, 2026 |
| CVE-2026-82065 | Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82064 | Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-82063 | Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial of Service | MEDIUM | 6.0 | Sep 8, 2026 |
| CVE-2026-82062 | Improper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate Bypass | HIGH | 7.0 | Sep 8, 2026 |
| CVE-2026-82061 | Use-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of Service | HIGH | 7.2 | Sep 8, 2026 |
| CVE-2026-82060 | Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image Lookups | LOW | 2.3 | Sep 8, 2026 |
| CVE-2026-82059 | Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service | MEDIUM | 6.0 | Sep 8, 2026 |
| CVE-2026-82058 | Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of Service | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82057 | Type Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of Service | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82056 | Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of Service | MEDIUM | 6.0 | Sep 8, 2026 |
| CVE-2026-82055 | Null Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of Service | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82054 | Uncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of Service | HIGH | 7.1 | Sep 8, 2026 |
| CVE-2026-82053 | Improper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role Assignment | HIGH | 7.6 | Sep 8, 2026 |
| CVE-2026-82052 | $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars | HIGH | 7.1 | Sep 8, 2026 |
Showing 1 to 25 of 171 CVEs