mongodb
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting mongodb.
- CVE-2026-19003MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings7.8
- CVE-2026-19004MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters8.1
- CVE-2026-18888MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data6.5
- CVE-2026-19001MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names9.8
- CVE-2026-19002Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver8.1
- CVE-2026-19503Insufficient OIDC endpoint validation could invoke unintended local protocol handlers4.8
- CVE-2026-19502Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI5.5
- CVE-2026-18710Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization6.5
- CVE-2026-18712Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections8.1
- CVE-2026-18711Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure7.1
- CVE-2026-18709Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency6.4
- CVE-2026-18698Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command5.4
- CVE-2026-18690Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections8.1
- CVE-2026-18699Improper Input Validation in MongoDB Query Planner Leads to Denial of Service6.5
- CVE-2026-18691Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure8.8