Where
-Infinity
0

MongoDB MongoDB ServerImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination

Risk 35
Severity
6
First published (updated )

MongoDB MongoDB ServerLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader

Risk 44
Severity
6.3
First published (updated )

MongoDB MongoDBPost-authentication use-after-free in server-side JavaScript BSON-to-array conversion

Risk 79
Severity
8.7
First published (updated )

MongoDB MongoDBUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow

Risk 33
Severity
8.7
EPSS
0.34%
First published (updated )

MongoDB MongoDB ServerKeyfile contents are in MongoDB Server logs

Risk 27
Severity
6.8
EPSS
0.12%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBStack memory disclosure in filemd5 command

Risk 29
Severity
7.1
EPSS
0.22%
First published (updated )

MongoDB MongoDBServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.

Risk 43
Severity
7.2
EPSS
0.30%
First published (updated )

MongoDB MongoDBGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )

MongoDB MongoDBSensitive data could be written to mongod.log

Risk 27
Severity
6.8
EPSS
0.11%
First published (updated )

MongoDB MongoDBMetadata name collision on $-prefixed fields causes post-auth server crash

Risk 29
Severity
7.1
EPSS
0.37%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input

Risk 29
Severity
7.1
EPSS
0.32%
First published (updated )

MongoDB MongoDBCrafted cross-shard merge aggregation crashes MongoDB Server

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )

MongoDB MongoDBServer crashes in case of the use of exchange

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )

MongoDB MongoDB ServerAggregation sub-pipeline null dereference may allow DoS via crafted getMore

Risk 29
Severity
7.1
EPSS
0.31%
First published (updated )

MongoDB MongoDBAuthenticate command with specific mechanism parameter can trigger server crash

Risk 31
Severity
8.2
EPSS
0.35%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB ServerCalling createIndex with certain index types can crash mongod

Risk 29
Severity
7.1
EPSS
0.24%
First published (updated )

MongoDB MongoDBPost-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators

Risk 27
Severity
5.3
EPSS
0.05%
First published (updated )

MongoDB MongoDBPost-authentication use-after-free error in $_internalJsEmit and mapreduce commands

Risk 51
Severity
7.7
EPSS
0.26%
First published (updated )

MongoDB MongoDBSchema validation log messages may not redact user data

Risk 19
Severity
4.8
EPSS
0.04%
First published (updated )

MongoDB MongoDBPost-auth memory exhaustion via bitwise match expressions

Risk 29
Severity
7.1
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBFlatBSON Duplicate Field Index Drift

Risk 56
Severity
8.7
EPSS
0.07%
First published (updated )

MongoDB MongoDB ServerPost-auth null pointer dereference when aggregating against a view with empty search pipeline

Risk 29
Severity
7.1
EPSS
0.04%
First published (updated )

MongoDB MongoDBMD5 checksum creation may cause availability loss

Risk 31
Severity
7.1
EPSS
0.04%
First published (updated )

MongoDB MongoDBMemory safety issues in slot-based execution hash table spill

Risk 37
Severity
6.1
EPSS
0.08%
First published (updated )

MongoDB MongoDBExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators

Risk 56
Severity
8.8
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBStack memory disclosure in filemd5 command

Risk 29
Severity
7.1
EPSS
0.03%
First published (updated )

MongoDB MongoDBMongod can run out of stack memory when expressions create deeply nested documents

Risk 43
Severity
7.5
First published (updated )

MongoDB MongoDBMongoDB Server may crash when inserting large documents

Risk 43
Severity
7.5
First published (updated )

MongoDB MongoDB ServerInternal ResourceId collision may affect unrelated collections

Risk 29
Severity
7.1
EPSS
0.04%
First published (updated )

MongoDB MongoDB ServerPre-Authentication Memory Exhaustion Denial of Service in MongoDB Server

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203