Mongodb
This hub aggregates every CVE we track for Mongodb, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
146
CVEs tracked
3
Critical
34
High
1
In CISA KEV
Severity distribution
MEDIUM106HIGH34LOW3CRITICAL3
Monthly trend
1
1
1
0
0
0
2
4
0
4
5
0
4
2
5
2
0
9
4
2
8
15
25
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mongodb.
- CVE-2026-13055Server crash via aggregation pipeline expression with compound wildcard index specification6.5
- CVE-2026-13056A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM6.5
- CVE-2026-13057Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META5.3
- CVE-2026-13058Transaction Command Insufficient Input Validation Leading to Process Termination6.5
- CVE-2026-13059Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass8.1
- CVE-2026-9737Find command with $meta sort can lead to crash6.5
- CVE-2026-13060$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access6.5
- CVE-2026-13061Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage4.3
- CVE-2026-13062MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters6.5
- CVE-2026-13063libmongocrypt Improper Input Validation Leading to Process Termination4.3
- CVE-2026-13064MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service6.5
- CVE-2026-13065MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination6.5
- CVE-2026-13066Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure6.5
- CVE-2026-13067tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket6.3
- CVE-2026-13068MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse4.2
Product normalization is registry-driven with AI assist and human review. How it works