Known Vulnerabilities for MongoDB Server by MongoDB
Listed below are 10 of the newest known vulnerabilities associated with "MongoDB Server" by "MongoDB".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45689 json | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-45688 json | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-34163 json | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-11933 json | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to Jav... | Not Provided | 2026-06-12 | 2026-06-13 |
| CVE-2026-9750 json | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere wi... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-9747 json | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-9743 json | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If ... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-9740 json | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sendi... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-9735 json | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When c... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-8843 json | Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a... | Not Provided | 2026-05-18 | 2026-05-18 |