MongoDB, Inc.

First CVE: Aug 6, 2019Active for: 7 years
173
CVEs Published
More CVEs Published than 77% of tracked CNAs
21.6
Avg CVEs / Year
More Avg CVEs / Year than 70% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked CNAs
0.6%
In CISA KEV
Higher KEV Rate than 86% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by MongoDB, Inc. as a CNA, 76.9% affect products that MongoDB, Inc. develops as a vendor.

76.9%
23.1%
Self-reported: 133Third-party: 40

Of all the CVEs published that affect products developed by MongoDB, Inc., 87.5% are self-published by MongoDB, Inc. as a CNA.

87.5%
12.5%
Self-published: 133Published by other CNAs: 19

Trends Over Time

The number and severity of CVEs published by MongoDB, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2019
6 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by MongoDB, Inc. as a CNA, regardless of affected vendor or product.

173 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0
Dec 19, 20257.598YESYES
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongo
May 12, 20268.837NONO
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory co
Jul 22, 20268.136NONO
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient vali
Jul 22, 20268.135NONO
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privile
Jun 12, 20268.835NONO
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to pr
Jul 22, 20267.834NONO
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the serv
Jun 9, 20268.134NONO
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read
Jul 22, 20267.733NONO
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's ha
Jun 9, 20267.533NONO
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network
May 6, 20267.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA173 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local20 (11.6%)
Network149 (86.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (2.3%)
Attack Complexity
Low155 (89.6%)
High18 (10.4%)
Unknown0 (0.0%)
User Interaction
None163 (94.2%)
Unknown0 (0.0%)
Required10 (5.8%)
Privileges Required
Low108 (62.4%)
High10 (5.8%)
None55 (31.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (173 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 86th percentile
Metasploit
2 CVEs
1.2% of CVEs· 88th percentile
Nuclei
1 CVE
0.6% of CVEs· 76th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by MongoDB, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by MongoDB, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs