Mongodb

Mongodb

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 17.03.2026 19:00:07
  • Zuletzt bearbeitet 18.03.2026 14:52:44

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

  • EPSS 0.05%
  • Veröffentlicht 17.03.2026 15:53:57
  • Zuletzt bearbeitet 18.03.2026 14:52:44

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

  • EPSS 0.03%
  • Veröffentlicht 17.03.2026 15:50:21
  • Zuletzt bearbeitet 18.03.2026 14:52:44

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

  • EPSS 0.07%
  • Veröffentlicht 12.03.2026 19:14:47
  • Zuletzt bearbeitet 13.03.2026 19:00:34

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider th...

  • EPSS 0.04%
  • Veröffentlicht 11.03.2026 18:02:57
  • Zuletzt bearbeitet 13.03.2026 18:24:36

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and ...

  • EPSS 0.05%
  • Veröffentlicht 10.02.2026 18:54:50
  • Zuletzt bearbeitet 25.02.2026 16:45:10

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

  • EPSS 0.05%
  • Veröffentlicht 10.02.2026 18:52:52
  • Zuletzt bearbeitet 25.02.2026 17:17:56

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

  • EPSS 0.05%
  • Veröffentlicht 10.02.2026 18:49:32
  • Zuletzt bearbeitet 25.02.2026 17:11:10

Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.

  • EPSS 0.03%
  • Veröffentlicht 10.02.2026 18:39:11
  • Zuletzt bearbeitet 25.02.2026 16:54:40

Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.

  • EPSS 0.05%
  • Veröffentlicht 10.02.2026 18:30:40
  • Zuletzt bearbeitet 25.02.2026 16:46:13

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.