MongoDB, Inc.
First CVE: Aug 6, 2019Active for: 7 years
173
CVEs Published
More CVEs Published than 77% of tracked CNAs
21.6
Avg CVEs / Year
More Avg CVEs / Year than 70% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked CNAs
0.6%
In CISA KEV
Higher KEV Rate than 86% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by MongoDB, Inc. as a CNA, 76.9% affect products that MongoDB, Inc. develops as a vendor.
76.9%
23.1%
Self-reported: 133Third-party: 40
Of all the CVEs published that affect products developed by MongoDB, Inc., 87.5% are self-published by MongoDB, Inc. as a CNA.
87.5%
12.5%
Self-published: 133Published by other CNAs: 19
Trends Over Time
The number and severity of CVEs published by MongoDB, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2019
6 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by MongoDB, Inc. as a CNA, regardless of affected vendor or product.
173 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14847HIGH Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 | Dec 19, 2025 | 7.5 | 98 | YES | YES |
CVE-2026-8053HIGH An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongo | May 12, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-13072HIGH When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory co | Jul 22, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-13059HIGH An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient vali | Jul 22, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-11933HIGH A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privile | Jun 12, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-14881HIGH When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to pr | Jul 22, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-9753HIGH The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the serv | Jun 9, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-13078HIGH A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read | Jul 22, 2026 | 7.7 | 33 | NO | NO |
CVE-2026-9740HIGH A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's ha | Jun 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-6691HIGH The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network | May 6, 2026 | 7.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA173 CVEs
63%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local20 (11.6%)
Network149 (86.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (2.3%)
Attack Complexity
Low155 (89.6%)
High18 (10.4%)
Unknown0 (0.0%)
User Interaction
None163 (94.2%)
Unknown0 (0.0%)
Required10 (5.8%)
Privileges Required
Low108 (62.4%)
High10 (5.8%)
None55 (31.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (173 CVEs).
CISA KEV
1 CVE
0.6% of CVEs· 86th percentile
Metasploit
2 CVEs
1.2% of CVEs· 88th percentile
Nuclei
1 CVE
0.6% of CVEs· 76th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by MongoDB, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by MongoDB, Inc. as a CNA — matched by CVE ID, not by organization name.