Vulnerabilidades en MongoDB

162 resultados
Análisis Vexday

MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.

CVE-2026-9752HIGHGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationEPSS 0.5%CVE-2026-9746HIGHServer crashes in case of the use of exchangeEPSS 0.5%CVE-2026-9749HIGHUsing MaxKey() may crash the serverEPSS 0.5%CVE-2026-9747HIGHCrafted cross-shard merge aggregation crashes MongoDB ServerEPSS 0.5%CVE-2026-9743HIGHAggregation sub-pipeline null dereference may allow DoS via crafted getMoreEPSS 0.5%CVE-2026-88031MEDIUMGridFS data deletion via query-operator injection in file IDs in the MongoDB Go DriverEPSS 0.5%CVE-2026-18706HIGHUse-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.5%CVE-2026-88025MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# DriverEPSS 0.5%CVE-2026-88024MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust DriverEPSS 0.5%CVE-2026-88023MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP LibraryEPSS 0.5%CVE-2026-88029MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python DriverEPSS 0.5%CVE-2026-88030MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby DriverEPSS 0.5%CVE-2026-81517HIGHMongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL ServiceEPSS 0.5%CVE-2026-88034MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ DriverEPSS 0.5%CVE-2026-88033MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java DriverEPSS 0.5%CVE-2026-82062HIGHImproper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate BypassEPSS 0.5%CVE-2026-81522HIGHCross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ DriverEPSS 0.5%CVE-2026-13064HIGHMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceEPSS 0.5%CVE-2026-6914HIGHMD5 checksum creation may cause availability lossEPSS 0.4%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.4%