Vulnerabilidades em MONGODB
155 resultadosAnálise Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-13065HIGHMongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationEPSS 0.5%CVE-2026-13064HIGHMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceEPSS 0.5%CVE-2026-18692HIGHUse-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.4%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.4%CVE-2026-9737HIGHFind command with $meta sort can lead to crashEPSS 0.4%CVE-2026-13072CRITICALMongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory CorruptionEPSS 0.4%CVE-2026-13056HIGHA user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAMEPSS 0.4%CVE-2026-19001CRITICALMongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesEPSS 0.4%CVE-2026-13060HIGH$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection AccessEPSS 0.4%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.4%CVE-2026-11933HIGHPost-authentication use-after-free in server-side JavaScript BSON-to-array conversionEPSS 0.4%CVE-2026-19004HIGHMongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output ParametersEPSS 0.4%CVE-2026-13066HIGHServer-Side JavaScript DBPointer BSON Serialization Memory DisclosureEPSS 0.4%CVE-2026-9750HIGHMetadata name collision on $-prefixed fields causes post-auth server crashEPSS 0.4%CVE-2026-82052HIGH$regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 charsEPSS 0.4%CVE-2026-9742HIGHAuthenticate command with specific mechanism parameter can trigger server crashEPSS 0.3%CVE-2026-9740HIGHUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowEPSS 0.3%CVE-2026-13078MEDIUMLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderEPSS 0.3%CVE-2026-18706HIGHUse-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.3%