CVE-2026-5170
- EPSS 0.2%
- Veröffentlicht 30.03.2026 15:28:57
- Zuletzt bearbeitet 02.04.2026 17:18:58
A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictable window when the cluster is being promoted from a replica set to a sharded cluster. This may cause a...
CVE-2026-4358
- EPSS 0.34%
- Veröffentlicht 17.03.2026 19:00:07
- Zuletzt bearbeitet 02.04.2026 12:16:02
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.
CVE-2026-4148
- EPSS 0.32%
- Veröffentlicht 17.03.2026 15:53:57
- Zuletzt bearbeitet 10.04.2026 17:38:37
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.
CVE-2026-4147
- EPSS 0.22%
- Veröffentlicht 17.03.2026 15:50:21
- Zuletzt bearbeitet 10.04.2026 17:40:20
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
CVE-2026-32248
- EPSS 0.63%
- Veröffentlicht 12.03.2026 19:14:47
- Zuletzt bearbeitet 13.03.2026 19:00:34
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider th...
CVE-2026-31872
- EPSS 0.37%
- Veröffentlicht 11.03.2026 18:02:57
- Zuletzt bearbeitet 13.03.2026 18:24:36
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and ...
CVE-2026-25613
- EPSS 0.24%
- Veröffentlicht 10.02.2026 18:54:50
- Zuletzt bearbeitet 25.02.2026 16:45:10
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
CVE-2026-1849
- EPSS 0.27%
- Veröffentlicht 10.02.2026 18:52:52
- Zuletzt bearbeitet 25.02.2026 17:17:56
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.
CVE-2026-1850
- EPSS 0.24%
- Veröffentlicht 10.02.2026 18:49:32
- Zuletzt bearbeitet 25.02.2026 17:11:10
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
CVE-2026-25609
- EPSS 0.17%
- Veröffentlicht 10.02.2026 18:39:11
- Zuletzt bearbeitet 25.02.2026 16:54:40
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.