CVE-2026-4358
- EPSS 0.06%
- Veröffentlicht 17.03.2026 19:00:07
- Zuletzt bearbeitet 18.03.2026 14:52:44
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.
CVE-2026-4148
- EPSS 0.05%
- Veröffentlicht 17.03.2026 15:53:57
- Zuletzt bearbeitet 18.03.2026 14:52:44
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.
CVE-2026-4147
- EPSS 0.03%
- Veröffentlicht 17.03.2026 15:50:21
- Zuletzt bearbeitet 18.03.2026 14:52:44
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
CVE-2026-32248
- EPSS 0.07%
- Veröffentlicht 12.03.2026 19:14:47
- Zuletzt bearbeitet 13.03.2026 19:00:34
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider th...
CVE-2026-31872
- EPSS 0.04%
- Veröffentlicht 11.03.2026 18:02:57
- Zuletzt bearbeitet 13.03.2026 18:24:36
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and ...
CVE-2026-25613
- EPSS 0.05%
- Veröffentlicht 10.02.2026 18:54:50
- Zuletzt bearbeitet 25.02.2026 16:45:10
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
CVE-2026-1849
- EPSS 0.05%
- Veröffentlicht 10.02.2026 18:52:52
- Zuletzt bearbeitet 25.02.2026 17:17:56
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.
CVE-2026-1850
- EPSS 0.05%
- Veröffentlicht 10.02.2026 18:49:32
- Zuletzt bearbeitet 25.02.2026 17:11:10
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
CVE-2026-25609
- EPSS 0.03%
- Veröffentlicht 10.02.2026 18:39:11
- Zuletzt bearbeitet 25.02.2026 16:54:40
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.
CVE-2026-25610
- EPSS 0.05%
- Veröffentlicht 10.02.2026 18:30:40
- Zuletzt bearbeitet 25.02.2026 16:46:13
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.