Known Vulnerabilities for products from MongoDB
Listed below are 20 of the newest known vulnerabilities associated with the vendor "MongoDB".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84970 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-84969 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-84968 json | Not Provided | 2026-09-03 | 2026-09-04 | |
| CVE-2026-84967 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-84966 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-84964 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-84963 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-81533 json | Not Provided | 2026-08-28 | 2026-08-31 | |
| CVE-2026-81532 json | Not Provided | 2026-08-28 | 2026-08-31 | |
| CVE-2026-81530 json | Not Provided | 2026-08-27 | 2026-08-28 | |
| CVE-2026-13078 json | A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a mo... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13077 json | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via ... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13076 json | An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by perfor... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13075 json | An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $ra... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13074 json | An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13073 json | An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted agg... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13072 json | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during ... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13071 json | An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions ... | Not Provided | 2026-07-22 | 2026-08-18 |
| CVE-2026-13070 json | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response fro... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13069 json | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafte... | Not Provided | 2026-07-22 | 2026-08-05 |
Known software with vulnerabilities from MongoDB
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Mongodb | Bson | 1.0.0 |
| Application | Mongodb | Js-bson | 0.0.5 |
| Application | Mongodb | Kubernetes Operator | 0.10 |
| Application | Mongodb | Libbson | 0.2.0 |
| Application | Mongodb | Libmongocrypt | 0.3.0 |
| Application | Mongodb | Mongodb | - |
| Application | Mongodb | Mongodb Enterprise Kubernetes Operator | 0.10 |
| Application | Mongodb | Ops Manager | 1.6.0 |