mongodb-inc
Latest CVEs
The 15 most recently published vulnerabilities affecting mongodb-inc.
- CVE-2026-93759Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist8.6
- CVE-2026-93760NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard8.2
- CVE-2026-93761Denial of service via unbounded regex matching in Mongoid's in-memory query matcher7.5
- CVE-2026-93762Data deletion and attribute disclosure via field-name method injection in in-memory queries9.8
- CVE-2026-93763Silent plaintext persistence via unresolved callable database name in encryption schema map6.5
- CVE-2026-93764Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation6.5
- CVE-2026-93765Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation9.1
- CVE-2026-93758Cross-principal document update, theft, and deletion via unvalidated id in nested attributes8.1
- CVE-2026-93395Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()5.3
- CVE-2026-93394libmongoc SCRAM client nonce-validation bypass3.7
- CVE-2026-93393Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream8.1
- CVE-2026-92757Malformed connection string may disable field level encryption5.5
- CVE-2026-92758Logs may collect sensitive information5.5
- CVE-2026-92756Combining encryption settings may disable encryption5.5
- CVE-2026-9101Prototype pollution in csv parsing4.3