Vulnerabilities in MongoDB

162 results
Vexday analysis

MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.

CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-18692HIGHUse-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.6%CVE-2026-9750HIGHMetadata name collision on $-prefixed fields causes post-auth server crashEPSS 0.6%CVE-2026-9748HIGH$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries inputEPSS 0.6%CVE-2026-82071HIGHInsufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteEPSS 0.5%CVE-2026-19001CRITICALMongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesEPSS 0.5%CVE-2026-9740HIGHUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowEPSS 0.5%CVE-2026-82061HIGHUse-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of ServiceEPSS 0.5%CVE-2026-9753HIGHServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.EPSS 0.5%CVE-2026-82075HIGHUncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-82064HIGHUnauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set MembersEPSS 0.5%CVE-2026-9742HIGHAuthenticate command with specific mechanism parameter can trigger server crashEPSS 0.5%CVE-2026-82067CRITICALImproper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at StartupEPSS 0.5%CVE-2026-19004HIGHMongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output ParametersEPSS 0.5%CVE-2026-82052HIGH$regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 charsEPSS 0.5%CVE-2026-13065HIGHMongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationEPSS 0.5%CVE-2026-81532HIGHBI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionEPSS 0.5%CVE-2026-81525HIGHCross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP DriverEPSS 0.5%CVE-2026-88036MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C DriverEPSS 0.5%CVE-2026-18711HIGHUse-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory DisclosureEPSS 0.5%