Mongodb
This hub aggregates every CVE we track for Mongodb, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
153
CVEs tracked
4
Critical
36
High
1
In CISA KEV
Severity distribution
MEDIUM110HIGH36CRITICAL4LOW3
Monthly trend
3
1
1
1
0
0
0
2
4
0
4
5
0
4
3
5
2
0
9
5
2
8
15
24
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Mongodb.
- CVE-2026-13055Server crash via aggregation pipeline expression with compound wildcard index specification6.5
- CVE-2026-13056A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM6.5
- CVE-2026-13057Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META5.3
- CVE-2026-13059Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass8.1
- CVE-2026-9737Find command with $meta sort can lead to crash6.5
- CVE-2026-13060$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access6.5
- CVE-2026-13061Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage4.3
- CVE-2026-13062MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters6.5
- CVE-2026-13063libmongocrypt Improper Input Validation Leading to Process Termination4.3
- CVE-2026-13064MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service6.5
- CVE-2026-13065MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination6.5
- CVE-2026-13066Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure6.5
- CVE-2026-13067tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket6.3
- CVE-2026-13068MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse4.2
- CVE-2026-13069Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion6.5
Product normalization is registry-driven with AI assist and human review. How it works