Vulnerabilidades em MongoDB
155 resultadosAnálise Vexday
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-18697HIGHImproper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongosEPSS 0.3%CVE-2026-9748HIGH$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries inputEPSS 0.3%CVE-2026-82062HIGHImproper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate BypassEPSS 0.3%CVE-2026-88024MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust DriverEPSS 0.3%CVE-2026-88025MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# DriverEPSS 0.3%CVE-2026-88023MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP LibraryEPSS 0.3%CVE-2026-18888HIGHMongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character dataEPSS 0.3%CVE-2026-9743HIGHAggregation sub-pipeline null dereference may allow DoS via crafted getMoreEPSS 0.3%CVE-2026-19002HIGHCrafted database metadata may cause memory corruption in MongoDB BI Connector ODBC DriverEPSS 0.3%CVE-2026-82071HIGHInsufficient Validation of Storage Engine Configuration Options in MongoDB Server Leads to Out-of-Bounds WriteEPSS 0.3%CVE-2026-9753HIGHServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.EPSS 0.3%CVE-2026-82069MEDIUMImproper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterEPSS 0.3%CVE-2026-88022HIGHUnauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for LaravelEPSS 0.3%CVE-2026-82057HIGHType Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of ServiceEPSS 0.3%CVE-2026-18701HIGHType Confusion in MongoDB Query Subsystem Leads to Denial of ServiceEPSS 0.3%CVE-2025-14911HIGHInteger Overflow in GridFS chunkSize Leading to Heap Allocation FailureEPSS 0.3%CVE-2026-82061HIGHUse-After-Free in MongoDB Server Query Execution Memory Tracking Subsystem Leads to Denial of ServiceEPSS 0.3%CVE-2026-82076HIGHInteger Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB ServerEPSS 0.3%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.3%CVE-2026-81532HIGHBI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory CorruptionEPSS 0.3%