LIVE · cybersecurity feed
Live wire
vendor

Mongodb

14 CVEs published in the last four months. Exploited flaws first.

Critical0
High11
Medium2
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-119338.8highmongodbA use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON docum85d ago
CVE-2026-80538.8highmongodbAn issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write115d ago
CVE-2026-41488.8highmongodbA use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who172d ago
CVE-2026-130598.1highmongodbAn authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected b45d ago
CVE-2026-97538.1highmongodbThe $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malfo88d ago
CVE-2026-130728.1highmongodbWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON d45d ago
CVE-2026-130787.7highmongodbA vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally regi45d ago
CVE-2026-97427.5highmongodbWhen OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter 88d ago
CVE-2026-83367.5highmongodbAfter invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map functi115d ago
CVE-2026-97407.5highmongodbA vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod proces88d ago
CVE-2026-130777.1highmongodbA missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds hea45d ago
CVE-2026-41476.5mediummongodbAn authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-craft172d ago
CVE-2026-43586.4mediummongodbA specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a doubl172d ago
CVE-2026-43592lowc driverA compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause172d ago

Filter the full tracker by Mongodb