MongoDB

MongoDB

192 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 22.07.2026 19:13:33
  • Zuletzt bearbeitet 18.08.2026 16:15:20

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response l...

Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 22.07.2026 19:13:04
  • Zuletzt bearbeitet 18.08.2026 16:13:59

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and requires the abili...

Medienbericht
  • EPSS 0.24%
  • Veröffentlicht 22.07.2026 19:12:42
  • Zuletzt bearbeitet 18.08.2026 16:13:21

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportiona...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 22.07.2026 19:12:11
  • Zuletzt bearbeitet 18.08.2026 16:11:00

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONCol...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 22.07.2026 19:11:20
  • Zuletzt bearbeitet 18.08.2026 16:06:54

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's p...

  • EPSS 0.38%
  • Veröffentlicht 12.06.2026 02:16:38
  • Zuletzt bearbeitet 22.06.2026 14:38:54

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where...

  • EPSS 0.35%
  • Veröffentlicht 09.06.2026 22:43:44
  • Zuletzt bearbeitet 23.07.2026 09:10:00

A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled m...

  • EPSS 0.12%
  • Veröffentlicht 09.06.2026 22:40:55
  • Zuletzt bearbeitet 23.07.2026 09:10:00

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

  • EPSS 0.22%
  • Veröffentlicht 09.06.2026 22:33:21
  • Zuletzt bearbeitet 23.07.2026 09:10:00

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command

  • EPSS 0.3%
  • Veröffentlicht 09.06.2026 22:30:57
  • Zuletzt bearbeitet 23.07.2026 09:10:00

The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated us...