Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.7
CVE-2026-13078
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…
MongoDB
No fix yet
HIGH 7.1
CVE-2026-13077
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi…
MongoDB
No fix yet
MEDIUM 6.5
CVE-2026-13075
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio…
MongoDB
No fix yet
MEDIUM 6.5
CVE-2026-13076
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ…
MongoDB
No fix yet
MEDIUM 5.3
CVE-2026-13074
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await…
MongoDB
No fix yet
HIGH 8.1
CVE-2026-13072
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…
MongoDB
Mitigation only
MEDIUM 6.5
CVE-2026-13069
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption f…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13071
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side…
MongoDB
No fix yet
MEDIUM 5.3
CVE-2026-13070
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during t…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13062
An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields th…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13064
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments,…
MongoDB
8.0.28 / 8.2.12+
MEDIUM 6.5
CVE-2026-13065
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expre…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13066
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory con…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13063
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a cr…
MongoDB
8.2.12 / 8.3.7+
MEDIUM 6.3
CVE-2026-13067
When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configur…
MongoDB
8.0.28 / 8.3.7+
HIGH 8.1
CVE-2026-13059
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access con…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13055
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to han…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13056
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the serv…
MongoDB
8.0.28 / 8.3.7+
MEDIUM 6.5
CVE-2026-13057
An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls.
In sharded topologies, the $sea…
MongoDB
8.0.28 / 8.2.12+
MEDIUM 6.5
CVE-2026-13058
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with …
MongoDB
8.0.28 / 8.2.12+
MEDIUM 6.5
CVE-2026-13060
An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an incons…
MongoDB
7.0.39 / 8.0.28+
HIGH 8.8
CVE-2026-11933
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authe…
MongoDB
4.4.31 / 5.0.34+
MEDIUM 6.5
CVE-2026-9754
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
MongoDB
8.2.10 / 8.3.3+
HIGH 8.1
CVE-2026-9753
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory …
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9747
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9748
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But Pa…
MongoDB
7.0.35 / 8.0.10+
MEDIUM 6.5
CVE-2026-9749
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-pre…
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9750
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata pro…
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9752
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containi…
MongoDB
7.0.35 / 8.0.24+
MEDIUM 5.5
CVE-2026-9751
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
MongoDB
7.0.35 / 8.0.24+