Where
-Infinity
0

MongoDB MongoDBServer crash via aggregation pipeline expression with compound wildcard index specification

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBA user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META

Risk 38
Severity
6
First published (updated )

MongoDB MongoDBTransaction Command Insufficient Input Validation Leading to Process Termination

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass

Risk 62
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBFind command with $meta sort can lead to crash

Risk 29
Severity
7.1
EPSS
0.24%
First published (updated )

MongoDB MongoDB$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage

Risk 26
Severity
5.3
First published (updated )

MongoDB MongoDBMongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBlibmongocrypt Improper Input Validation Leading to Process Termination

Risk 38
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBMongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBServer-Side JavaScript DBPointer BSON Serialization Memory Disclosure

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBtlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket

Risk 51
Severity
7.2
First published (updated )

MongoDB MongoDBMongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse

Risk 22
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDBImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination

Risk 35
Severity
6
First published (updated )

MongoDB MongoDBMongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination

Risk 26
Severity
5.3
First published (updated )

MongoDB MongoDBAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service

Risk 33
Severity
6.9
First published (updated )

MongoDB MongoDBPost-authentication use-after-free in server-side JavaScript BSON-to-array conversion

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow

Risk 33
Severity
8.7
EPSS
0.34%
First published (updated )

MongoDB MongoDB ServerKeyfile contents are in MongoDB Server logs

Risk 27
Severity
6.8
EPSS
0.12%
First published (updated )

MongoDB MongoDBStack memory disclosure in filemd5 command

Risk 29
Severity
7.1
EPSS
0.22%
First published (updated )

MongoDB MongoDBServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.

Risk 43
Severity
7.2
EPSS
0.30%
First published (updated )

MongoDB MongoDBGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBSensitive data could be written to mongod.log

Risk 27
Severity
6.8
EPSS
0.11%
First published (updated )

MongoDB MongoDBMetadata name collision on $-prefixed fields causes post-auth server crash

Risk 29
Severity
7.1
EPSS
0.37%
First published (updated )

MongoDB MongoDBUsing MaxKey() may crash the server

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )

MongoDB MongoDB$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input

Risk 29
Severity
7.1
EPSS
0.32%
First published (updated )

MongoDB MongoDBCrafted cross-shard merge aggregation crashes MongoDB Server

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203