vendor

mongodb

127 thingsrelated by NVD

Its products

mongodb 52 c driver 11 bi connector 8 mongoid 8 bi connector odbc driver 7 c\# driver 6 c\+\+ driver 4 entity framework core provider 3 java driver 3 laravel mongodb 3 libmongocrypt 3 mongosql transition readiness tool 3 php driver 3 compass 2 go driver 2 php library 2 rust driver 2 sql schema builder cli 2 mongodb client encryption 1 odbc driver 1 ops manager 1 python driver 1 ruby driver 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are…
CVE-2026-93765
Severity critical
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema…
CVE-2026-93764
Severity medium
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application…
CVE-2026-93763
Severity medium
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally…
CVE-2026-93762
Severity critical
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an…
CVE-2026-93761
Severity high
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its…
CVE-2026-93760
Severity high
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a…
CVE-2026-93759
Severity high
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic…
CVE-2026-93758
Severity high
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data…
CVE-2026-93395
Severity medium
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the…
CVE-2026-93394
Severity low
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A…
CVE-2026-93393
Severity high
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in…
CVE-2026-92758
Severity medium
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable…
CVE-2026-92757
Severity medium
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption…
CVE-2026-92756
Severity medium
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory…
CVE-2026-89099
Severity high
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied…
CVE-2026-88036
Severity high
A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is…
CVE-2026-88035
Severity medium
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a…
CVE-2026-88034
Severity high
org.mongodb/mongodb-driver-core: MongoDB Java Driver: Data disclosure and denial of service via query-operator injection in GridFS file IDs
CVE-2026-88033
Severity high
mongodb-java-driver: mongodb-driver-reactivestreams: mongodb-crypt: MongoDB Java Driver: Denial of Service via use-after-free in…
CVE-2026-88032
Severity high
go.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver/v2: MongoDB Go Driver: Data deletion via query-operator injection in GridFS file…
CVE-2026-88031
Severity high
rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection
CVE-2026-88030
Severity high
pymongo: MongoDB Python Driver: Data disclosure and denial of service via query-operator injection
CVE-2026-88029
Severity high
Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel…
CVE-2026-88028
Severity medium
Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for…
CVE-2026-88027
Severity high
Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a…
CVE-2026-88026
Severity medium
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a…
CVE-2026-88025
Severity high
rust-mongodb: MongoDB Rust Driver (GridFS): Data disclosure and deletion via query-operator injection in file IDs.
CVE-2026-88024
Severity high
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a…
CVE-2026-88023
Severity high
Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an…
CVE-2026-88022
Severity high
MONGOCRYPT: MONGOCRYPT: Denial of Service via improper handling of encrypted data
CVE-2026-84971
Severity medium
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text…
CVE-2026-84970
Severity medium
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a…
CVE-2026-84969
Severity low
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially…
CVE-2026-84968
Severity medium
An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be…
CVE-2026-84966
Severity medium
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a…
CVE-2026-84965
Severity medium
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that…
CVE-2026-84964
Severity high
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text…
CVE-2026-84963
Severity medium
MONGOCRYPT: MONGOCRYPT: Privilege escalation due to KMS request forgery
CVE-2026-84962
Severity medium
An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level…
CVE-2026-82076
Severity medium
An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client…
CVE-2026-82075
Severity high
MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal…
CVE-2026-82074
Severity medium
A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level…
CVE-2026-82073
Severity medium
Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to…
CVE-2026-82071
Severity high
A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access…
CVE-2026-82070
Severity medium
A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access…
CVE-2026-82069
Severity medium
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by…
CVE-2026-82068
Severity medium
Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to…
CVE-2026-82067
Severity high
A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read…
CVE-2026-82066
Severity high
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges…
CVE-2026-82065
Severity medium
A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set…
CVE-2026-82064
Severity high
A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of…
CVE-2026-82063
Severity medium
A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the…
CVE-2026-82062
Severity medium
A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read…
CVE-2026-82061
Severity high
In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with…
CVE-2026-82060
Severity medium
An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being…
CVE-2026-82059
Severity medium
A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod…
CVE-2026-82058
Severity medium
A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By…
CVE-2026-82057
Severity medium
A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under…
CVE-2026-82056
Severity medium
A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a…
CVE-2026-82055
Severity medium
A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command…
CVE-2026-82054
Severity medium
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication…
CVE-2026-82053
Severity high
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server…
CVE-2026-82052
Severity medium
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an…
CVE-2026-81533
Severity high
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement…
CVE-2026-81532
Severity high
A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material…
CVE-2026-81530
Severity medium
Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an…
CVE-2026-81529
Severity high
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a…
CVE-2026-81528
Severity medium
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both…
CVE-2026-81527
Severity medium
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it…
CVE-2026-81526
Severity medium
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before…
CVE-2026-81525
Severity high
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without…
CVE-2026-81524
Severity medium
A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier…
CVE-2026-81523
Severity medium
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those…
CVE-2026-81522
Severity high
go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite
CVE-2026-81521
Severity high
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by…
CVE-2026-81520
Severity high
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake…
CVE-2026-81518
Severity high
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection…
CVE-2026-81517
Severity high
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop…
CVE-2026-81490
Severity high
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the…
CVE-2026-77586
Severity high
In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL…
CVE-2026-77184
Severity medium
The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report…
CVE-2026-76798
Severity medium
The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading…
CVE-2026-76797
Severity medium
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user…
CVE-2026-76794
Severity medium
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both…
CVE-2026-75573
Severity medium
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld…
CVE-2026-75159
Severity high
MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an…
CVE-2026-19503
Severity medium
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on…
CVE-2026-19502
Severity medium
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a…
CVE-2026-19004
Severity high
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write…
CVE-2026-19003
Severity high
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an…
CVE-2026-19002
Severity high
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long…
CVE-2026-19001
Severity critical
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the…
CVE-2026-18888
Severity medium
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted…
CVE-2026-18712
Severity high
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal…
CVE-2026-18711
Severity high
org.mongodb/mongodb-driver: MongoDB Driver: Credential disclosure via cleartext logging during client initialization
CVE-2026-18710
Severity medium
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an…
CVE-2026-18709
Severity medium
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control…
CVE-2026-18708
Severity medium
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to…
CVE-2026-18707
Severity medium
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and…
CVE-2026-18706
Severity medium

← Previous 1 of 2 Next →