Vulnerabilidades en MONGODB

162 resultados
Análisis Vexday

MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.

CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-18692HIGHUse-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.6%CVE-2026-9750HIGHMetadata name collision on $-prefixed fields causes post-auth server crashEPSS 0.6%CVE-2026-9748HIGH$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries inputEPSS 0.6%CVE-2026-82071HIGHInsufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteEPSS 0.5%CVE-2026-19001CRITICALMongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesEPSS 0.5%CVE-2026-9740HIGHUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowEPSS 0.5%CVE-2026-82061HIGHUse-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of ServiceEPSS 0.5%CVE-2026-9753HIGHServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.EPSS 0.5%CVE-2026-82075HIGHUncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of ServiceEPSS 0.5%CVE-2026-82064HIGHUnauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set MembersEPSS 0.5%CVE-2026-9742HIGHAuthenticate command with specific mechanism parameter can trigger server crashEPSS 0.5%CVE-2026-82067CRITICALImproper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at StartupEPSS 0.5%CVE-2026-19004HIGHMongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output ParametersEPSS 0.5%CVE-2026-82052HIGH$regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 charsEPSS 0.5%CVE-2026-13065HIGHMongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationEPSS 0.5%CVE-2026-81532HIGHBI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionEPSS 0.5%CVE-2026-81525HIGHCross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP DriverEPSS 0.5%CVE-2026-88036MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C DriverEPSS 0.5%CVE-2026-18711HIGHUse-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory DisclosureEPSS 0.5%