Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 122

All 122 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness types associated with the MongoDB Server product from MongoDB Inc. It aggregates vulnerability data to provide a comprehensive overview of security issues affecting this specific database management system. The content includes various categories of weaknesses, such as improper input validation, authentication bypasses, and resource management errors, covering a significant historical range of disclosed security incidents. Readers can utilize this resource to track official advisories released by MongoDB Inc., gaining insight into how the vendor addresses and resolves identified security flaws over time. Additionally, the page allows users to understand the broader context of specific weakness classes within the MongoDB ecosystem, revealing patterns and trends in how these vulnerabilities are exploited or mitigated. Users can also look up the vulnerability history of MongoDB Server, observing the evolution of its security posture and the frequency of reported issues across different versions and releases. This aggregation serves as a centralized reference for security researchers, system administrators, and developers seeking to assess risks related to MongoDB deployments. By examining the compiled data, stakeholders can better evaluate the impact of known weaknesses on their infrastructure and make informed decisions regarding patching and configuration hardening. The information presented is derived from multiple authoritative sources, ensuring accuracy and relevance for those monitoring MongoDB Server security.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-9750 Metadata name collision on $-prefixed fields causes post-auth server crash CWE-617 6.5 Medium2026-06-09
CVE-2026-9749 Using MaxKey() may crash the server CWE-617 6.5 Medium2026-06-09
CVE-2026-9748 $_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input CWE-617 6.5 Medium2026-06-09
CVE-2026-9747 Crafted cross-shard merge aggregation crashes MongoDB Server CWE-617 6.5 Medium2026-06-09
CVE-2026-9746 Server crashes in case of the use of exchange CWE-617 6.5 Medium2026-06-09
CVE-2026-9743 Aggregation sub-pipeline null dereference may allow DoS via crafted getMore CWE-476 6.5 Medium2026-06-09
CVE-2026-9742 Authenticate command with specific mechanism parameter can trigger server crash CWE-1287 7.5 High2026-06-09
CVE-2026-9741 Client side encryption fails to encrypt values in a $vectorSearch CWE-319 6.5 Medium2026-06-09
CVE-2026-8843 Calling createIndex with certain index types can crash mongod CWE-617 6.5 Medium2026-05-18
CVE-2026-8202 Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators CWE-770 4.3 Medium2026-05-13
CVE-2026-8336 Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands CWE-416 7.5 High2026-05-13
CVE-2026-8201 Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields CWE-416 6.4 Medium2026-05-13
CVE-2026-8200 Schema validation log messages may not redact user data CWE-532 2.7 Low2026-05-13
CVE-2026-8199 Post-auth memory exhaustion via bitwise match expressions CWE-1325 6.5 Medium2026-05-13
CVE-2026-8053 FlatBSON Duplicate Field Index Drift CWE-787 8.8 High2026-05-12
CVE-2026-8063 Post-auth null pointer dereference when aggregating against a view with empty search pipeline CWE-476 6.5 Medium2026-05-07
CVE-2026-6915 Flaw in the updateUser Command May Allow Unauthorized Configuration Change CWE-1284 6.3 Medium2026-04-29
CVE-2026-6914 MD5 checksum creation may cause availability loss CWE-191 6.5 Medium2026-04-29
CVE-2026-5170 Users could trigger a crash of mongod primaries during promotion to sharded CWE-617 5.3 Medium2026-03-30
CVE-2026-4358 Memory safety issues in slot-based execution hash table spill CWE-415 6.4 Medium2026-03-17
CVE-2026-4148 ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators CWE-416 8.8 High2026-03-17
CVE-2026-4147 Stack memory disclosure in filemd5 command CWE-457 6.5 Medium2026-03-17
CVE-2026-25613 An unsafe cast in the MongoDB query planner can result in a segmentation fault. CWE-704 6.5 Medium2026-02-10
CVE-2026-1849 Mongod can run out of stack memory when expressions create deeply nested documents CWE-674 6.5 Medium2026-02-10
CVE-2026-1850 An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification CWE-770 6.5 Medium2026-02-10
CVE-2026-25609 profile command may permit unauthorized configuration CWE-862 5.4 Medium2026-02-10
CVE-2026-25610 Invalid $geoNear index hint may cause server crash CWE-617 6.5 Medium2026-02-10
CVE-2026-1848 Connections received from the proxy port may not count towards total accepted connections CWE-770 7.5 High2026-02-10
CVE-2026-1847 MongoDB Server may crash when inserting large documents CWE-770 6.5 Medium2026-02-10
CVE-2026-25612 Internal ResourceId collision may affect unrelated collections CWE-412 6.5 Medium2026-02-10

All 122 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.