Known vulnerabilities in MongoDB, Inc. MongoDB

Vendor: MongoDB, Inc.
Website: https://www.mongodb.com/
Total Security Bulletins: 28

Security bulletins (28)

Secuity bulletin Severity Status Published
SB2026022327: Use-after-free in MongoDB Low
Patched
23.02.2026
SB2026021331: Multiple vulnerabilities in MongoDB Server Medium
Patched
13.02.2026
SB2025122318: Information disclosure in MongoDB server High
Patched Exploited
23.12.2025
SB20250711109: Information disclosure in MongoDB Medium
Patched Public exploit
11.07.2025
SB20250711108: Denial of service in MongoDB Medium
Patched
11.07.2025
SB2025070329: MongoDB Server update for MongoDB driver for C High
Patched
03.07.2025
SB2025070253: Remote denial of service in MongoDB Medium
Patched
02.07.2025
SB2025062502: Input validation error in MongoDB Medium
Patched
25.06.2025
SB2025062444: Input validation error in MongoDB High
Patched
24.06.2025
SB2025062440: Improper access control in MongoDB Medium
Patched
24.06.2025
SB2025062432: Externally Controlled Reference to a Resource in Another Sphere in MongoDB Medium
Patched
24.06.2025
SB2025062423: Missing Authorization in MongoDB Medium
Patched
24.06.2025
SB2025020512: Improper Authorization in MongoDB Enterprise Server Low
Patched
05.02.2025
SB2024030782: MitM attack in MongoDB Server Medium
Patched
07.03.2024
SB2023112015: Improper Certificate Validation in MongoDB Medium
Patched
20.11.2023
SB2020112512: Multiple vulnerabilities in MongoDB Medium
Patched
25.11.2020
SB2020051301: Authorization bypass in MongoDB Server Low
Patched
13.05.2020
SB2019083011: Privilege escalation in MongoDB for Windows Low
Patched
30.08.2019
SB2019083012: Security restrictions bypass in MongoDB Low
Patched
30.08.2019
SB2019080702: Improper authentication in MongoDB Server Low
Patched
07.08.2019


Showing elements 1 - 20 out of 28