Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured...
MongoDB CVEs
33 high and critical vulnerabilities covered by CVE Brief since 2025-07-07, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
31 CVEs in the last 12 months
Products
- MongoDB Server10
- BI Connector5
- BI Connector ODBC Driver3
- C++ Driver2
- Rust Driver2
- C Driver1
- Java Driver1
- Ruby Driver1
16 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structur...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structu...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structu...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied struc...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structure...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structu...
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structu...
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor...
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to...
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An a...
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a...
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does no...
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity...
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning b...
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bo...
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text re...
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before...
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup...
The MongoDB BI Connector ODBC Driver is susceptible to a buffer overflow during metadata retrieval, which may lead to process termination or arbitrary...
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal refe...
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechani...
When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that en...
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline proc...
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access cont...
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the...
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client
Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation
When tlsInsecure=False appears in a connection string, certificate validation is disabled
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to...