Vulnerabilities in MongoDB
162 resultsVexday analysis
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-82054HIGHUncontrolled Resource Consumption in MongoDB Server JSON Pointer Parser Leads to Denial of ServiceEPSS 0.4%CVE-2026-82058HIGHUnhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of ServiceEPSS 0.4%CVE-2026-82068HIGHPersistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of ServiceEPSS 0.4%CVE-2026-18695HIGHImproper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of ServiceEPSS 0.4%CVE-2026-13056HIGHA user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAMEPSS 0.4%CVE-2026-82065HIGHInsufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted MetadataEPSS 0.4%CVE-2026-82055HIGHNull Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of ServiceEPSS 0.4%CVE-2026-18701HIGHType Confusion in MongoDB Query Subsystem Leads to Denial of ServiceEPSS 0.4%CVE-2026-13058HIGHTransaction Command Insufficient Input Validation Leading to Process TerminationEPSS 0.4%CVE-2026-13063MEDIUMlibmongocrypt Improper Input Validation Leading to Process TerminationEPSS 0.4%CVE-2026-13060HIGH$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection AccessEPSS 0.4%CVE-2026-18696HIGHImproper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on CollectionsEPSS 0.4%CVE-2026-18694HIGHOut-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory DisclosureEPSS 0.4%CVE-2026-18688HIGHOut-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory DisclosureEPSS 0.4%CVE-2026-88027HIGHMass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for LaravelEPSS 0.4%CVE-2026-82066MEDIUMHeap Out-of-Bounds Read in MongoDB Server Query Planning ComponentEPSS 0.4%CVE-2026-11933HIGHPost-authentication use-after-free in server-side JavaScript BSON-to-array conversionEPSS 0.4%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.4%CVE-2026-18708MEDIUMImproper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query ScopesEPSS 0.4%CVE-2026-9754HIGHStack memory disclosure in filemd5 commandEPSS 0.4%