Vulnerabilities in MongoDB

50 results
Vexday analysis

MongoDB apresenta 23 vulnerabilidades catalogadas, com concentração recente de 17 divulgações nos últimos 90 dias, indicando atividade elevada de descoberta de falhas. Nenhuma das vulnerabilidades está sob ataque ativo (KEV) e não há críticas de CVSS, reduzindo o risco imediato, mas a fraqueza dominante em autenticação/autorização (CWE-617) merece monitoramento contínuo em ambientes de produção.

CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.2%CVE-2026-13077HIGHOut-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn DataEPSS 0.2%CVE-2026-13060HIGH$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection AccessEPSS 0.2%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.2%CVE-2026-9737HIGHFind command with $meta sort can lead to crashEPSS 0.2%CVE-2026-13075HIGH$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationEPSS 0.2%CVE-2026-13058HIGHTransaction Command Insufficient Input Validation Leading to Process TerminationEPSS 0.2%CVE-2026-13064HIGHMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceEPSS 0.2%CVE-2026-13063MEDIUMlibmongocrypt Improper Input Validation Leading to Process TerminationEPSS 0.2%CVE-2026-13066HIGHServer-Side JavaScript DBPointer BSON Serialization Memory DisclosureEPSS 0.2%CVE-2026-9754HIGHStack memory disclosure in filemd5 commandEPSS 0.2%CVE-2026-13073MEDIUMMongoDB Aggregation Command Invariant Assertion Failure Leading to Process TerminationEPSS 0.2%CVE-2026-13078MEDIUMLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderEPSS 0.2%CVE-2026-5170MEDIUMUsers could trigger a crash of mongod primaries during promotion to shardedEPSS 0.2%CVE-2025-12119MEDIUMBulk write with options may read invalid memoryEPSS 0.2%CVE-2026-6915MEDIUMFlaw in the updateUser Command May Allow Unauthorized Configuration ChangeEPSS 0.2%CVE-2026-13061MEDIUMImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2026-13069HIGHQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource ExhaustionEPSS 0.2%