Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness types associated with the MongoDB Server product from MongoDB Inc. It aggregates vulnerability data to provide a comprehensive overview of security issues affecting this specific database management system. The content includes various categories of weaknesses, such as improper input validation, authentication bypasses, and resource management errors, covering a significant historical range of disclosed security incidents. Readers can utilize this resource to track official advisories released by MongoDB Inc., gaining insight into how the vendor addresses and resolves identified security flaws over time. Additionally, the page allows users to understand the broader context of specific weakness classes within the MongoDB ecosystem, revealing patterns and trends in how these vulnerabilities are exploited or mitigated. Users can also look up the vulnerability history of MongoDB Server, observing the evolution of its security posture and the frequency of reported issues across different versions and releases. This aggregation serves as a centralized reference for security researchers, system administrators, and developers seeking to assess risks related to MongoDB deployments. By examining the compiled data, stakeholders can better evaluate the impact of known weaknesses on their infrastructure and make informed decisions regarding patching and configuration hardening. The information presented is derived from multiple authoritative sources, ensuring accuracy and relevance for those monitoring MongoDB Server security.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-13055 Server crash via aggregation pipeline expression with compound wildcard index specification CWE-617 6.5 Medium2026-07-22
CVE-2026-13056 A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM CWE-1325 6.5 Medium2026-07-22
CVE-2026-13057 Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META CWE-20 5.3 Medium2026-07-22
CVE-2026-13058 Transaction Command Insufficient Input Validation Leading to Process Termination CWE-617 7.1 High2026-07-22
CVE-2026-13059 Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass CWE-807 8.1 High2026-07-22
CVE-2026-9737 Find command with $meta sort can lead to crash CWE-617 6.5 Medium2026-07-22
CVE-2026-13060 $graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access CWE-863 6.5 Medium2026-07-22
CVE-2026-13061 Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage CWE-863 4.3 Medium2026-07-22
CVE-2026-13062 MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters CWE-441 6.5 Medium2026-07-22
CVE-2026-13063 libmongocrypt Improper Input Validation Leading to Process Termination CWE-190 4.3 Medium2026-07-22
CVE-2026-13064 MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service CWE-407 6.5 Medium2026-07-22
CVE-2026-13065 MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination CWE-476 6.5 Medium2026-07-22
CVE-2026-13066 Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure CWE-843 6.5 Medium2026-07-22
CVE-2026-13067 tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket CWE-863 6.3 Medium2026-07-22
CVE-2026-13068 MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse CWE-863 4.2 Medium2026-07-22
CVE-2026-13069 Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion CWE-770 6.5 Medium2026-07-22
CVE-2026-13070 Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination CWE-476 5.3 Medium2026-07-22
CVE-2026-13071 Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termination CWE-416 6.5 Medium2026-07-22
CVE-2026-13072 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption CWE-122 8.1 High2026-07-22
CVE-2026-13073 MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination CWE-617 4.3 Medium2026-07-22
CVE-2026-13074 Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service CWE-770 5.3 Medium2026-07-22
CVE-2026-13075 $rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation CWE-770 6.5 Medium2026-07-22
CVE-2026-13076 Aggregation Framework Memory Exhaustion Leading to Process Termination CWE-770 6.5 Medium2026-07-22
CVE-2026-13077 Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data CWE-125 7.1 High2026-07-22
CVE-2026-13078 Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader CWE-862 7.7 High2026-07-22
CVE-2026-9740 Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow CWE-674 7.5 High2026-06-09
CVE-2026-9735 Keyfile contents are in MongoDB Server logs CWE-532 5.5 Medium2026-06-09
CVE-2026-9753 Server crash via malformed binary diff passed to $_internalApplyOplogUpdate. CWE-1287 8.1 High2026-06-09
CVE-2026-9752 GeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation CWE-476 6.5 Medium2026-06-09
CVE-2026-9751 Sensitive data could be written to mongod.log CWE-532 5.5 Medium2026-06-09

All 122 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.