Known Vulnerabilities for MongoDB Server by MongoDB
Listed below are 10 of the newest known vulnerabilities associated with "MongoDB Server" by "MongoDB".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34163 json | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-9750 json | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere wi... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-9747 json | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-9743 json | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If ... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-9740 json | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sendi... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-9735 json | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When c... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-8843 json | Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a... | Not Provided | 2026-05-18 | 2026-05-18 |
| CVE-2026-8336 json | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a ... | Not Provided | 2026-05-13 | 2026-05-15 |
| CVE-2026-8202 json | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim,... | Not Provided | 2026-05-13 | 2026-05-13 |
| CVE-2026-8201 json | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-si... | Not Provided | 2026-05-13 | 2026-05-13 |