MongoDB, Inc. maintains a focused portfolio of database and tooling products—including MongoDB server, language drivers, and administrative tools such as Compass and MongoDB Shell—that occupy a prominent position in the modern application data layer. The vendor's vulnerability profile is characterized by a recurring pattern of input-validation weaknesses, certificate-handling flaws, and assertion failures that reflect the parsing and protocol complexities inherent to a distributed database system and its client ecosystem. While the volume of disclosures is moderate relative to the vendor's prominence in the landscape, defenders should treat MongoDB security advisories seriously given the central role these products play in application infrastructure and data handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by MongoDB, Inc. over time
Of all the CVEs published by MongoDB, Inc. as a CNA, 76.9% affect products that MongoDB, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by MongoDB, Inc., 87.5% are self-published by MongoDB, Inc. as a CNA.
Signals from CVEs in this vendor scope (152 CVEs).
152 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14847HIGH Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 | Dec 19, 2025 | 7.5 | 98 | YES | YES |
CVE-2013-1892MEDIUM MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a den | Oct 1, 2013 | 6.0 | 57 | NO | YES |
CVE-2026-8053HIGH An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongo | May 12, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-11933HIGH A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privile | Jun 12, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-9753HIGH The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the serv | Jun 9, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-9740HIGH A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's ha | Jun 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-6691HIGH The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network | May 6, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-4148HIGH A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation p | Mar 17, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-8201HIGH A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering thi | May 13, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-6376CRITICAL MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issu | Jul 1, 2024 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (152 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by MongoDB, Inc..
Media articles that mention a CVE ID that affects a product developed by MongoDB, Inc. — matched by CVE ID, not by vendor name.