Known Vulnerabilities for products from Mongodb
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mongodb".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73618 json | Not Provided | 2026-08-13 | 2026-08-13 | |
| CVE-2026-73617 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-73562 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-73409 json | Not Provided | 2026-08-12 | 2026-08-14 | |
| CVE-2026-72881 json | Not Provided | 2026-08-10 | 2026-08-10 | |
| CVE-2026-72869 json | Not Provided | 2026-08-10 | 2026-08-11 | |
| CVE-2026-72857 json | Not Provided | 2026-08-13 | 2026-08-14 | |
| CVE-2026-72600 json | Not Provided | 2026-08-11 | 2026-08-11 | |
| CVE-2026-66750 json | Not Provided | 2026-07-28 | 2026-07-28 | |
| CVE-2026-59509 json | Not Provided | 2026-07-05 | 2026-07-06 | |
| CVE-2026-13070 json | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response fro... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13069 json | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafte... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13068 json | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active ... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13067 json | When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be valida... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13066 json | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in int... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13065 json | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13064 json | Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affec... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13063 json | An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory c... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13062 json | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encry... | Not Provided | 2026-07-22 | 2026-08-05 |
| CVE-2026-13061 json | An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions a... | Not Provided | 2026-07-22 | 2026-08-05 |
Known software with vulnerabilities from Mongodb
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Mongodb | Bson | 1.0.0 |
| Application | Mongodb | Js-bson | 0.0.5 |
| Application | Mongodb | Kubernetes Operator | 0.10 |
| Application | Mongodb | Libbson | 0.2.0 |
| Application | Mongodb | Libmongocrypt | 0.3.0 |
| Application | Mongodb | Mongodb | - |
| Application | Mongodb | Mongodb Enterprise Kubernetes Operator | 0.10 |
| Application | Mongodb | Ops Manager | 1.6.0 |