Vulnerabilidades em MongoDB
162 resultadosAnálise Vexday
MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.
CVE-2026-18697HIGHImproper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongosEPSS 0.4%CVE-2026-88022HIGHUnauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for LaravelEPSS 0.4%CVE-2026-13077HIGHOut-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn DataEPSS 0.4%CVE-2026-82057HIGHType Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of ServiceEPSS 0.4%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.4%CVE-2026-13075HIGH$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationEPSS 0.4%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.4%CVE-2026-81520HIGHMongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection ExhaustionEPSS 0.4%CVE-2026-77586HIGHMongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE OutputEPSS 0.4%CVE-2026-82076HIGHInteger Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB ServerEPSS 0.4%CVE-2026-82053HIGHImproper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role AssignmentEPSS 0.4%CVE-2026-88028HIGHUnauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for LaravelEPSS 0.4%CVE-2026-9737HIGHFind command with $meta sort can lead to crashEPSS 0.4%CVE-2026-81490HIGHMongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL ServiceEPSS 0.4%CVE-2026-82069MEDIUMImproper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterEPSS 0.4%CVE-2026-13072CRITICALMongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory CorruptionEPSS 0.4%CVE-2026-19002HIGHCrafted database metadata may cause memory corruption in MongoDB BI Connector ODBC DriverEPSS 0.4%CVE-2026-13058HIGHTransaction Command Insufficient Input Validation Leading to Process TerminationEPSS 0.4%CVE-2026-82055HIGHNull Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of ServiceEPSS 0.4%CVE-2026-82058HIGHUnhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of ServiceEPSS 0.4%