Vulnerabilidades en MONGODB
50 resultadosAnálisis Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2026-11933HIGHPost-authentication use-after-free in server-side JavaScript BSON-to-array conversionEPSS 0.4%CVE-2026-9750HIGHMetadata name collision on $-prefixed fields causes post-auth server crashEPSS 0.4%CVE-2026-9742HIGHAuthenticate command with specific mechanism parameter can trigger server crashEPSS 0.3%CVE-2026-9740HIGHUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowEPSS 0.3%CVE-2026-9748HIGH$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries inputEPSS 0.3%CVE-2026-13072CRITICALMongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory CorruptionEPSS 0.3%CVE-2026-9743HIGHAggregation sub-pipeline null dereference may allow DoS via crafted getMoreEPSS 0.3%CVE-2026-9753HIGHServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.EPSS 0.3%CVE-2026-13065HIGHMongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationEPSS 0.3%CVE-2026-13055HIGHServer crash via aggregation pipeline expression with compound wildcard index specificationEPSS 0.3%CVE-2026-13056HIGHA user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAMEPSS 0.3%CVE-2025-14911HIGHInteger Overflow in GridFS chunkSize Leading to Heap Allocation FailureEPSS 0.3%CVE-2026-13059HIGHImproper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control BypassEPSS 0.3%CVE-2026-9749HIGHUsing MaxKey() may crash the serverEPSS 0.3%CVE-2026-9752HIGHGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationEPSS 0.3%CVE-2026-9746HIGHServer crashes in case of the use of exchangeEPSS 0.3%CVE-2026-9747HIGHCrafted cross-shard merge aggregation crashes MongoDB ServerEPSS 0.3%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.3%CVE-2026-6914HIGHMD5 checksum creation may cause availability lossEPSS 0.3%