Track MongoDB with a free Huntertech account. Get outage alerts, watchlists, and cross-vendor monitoring in one place.

Try for free
0 advisories in the last 7 days/26 total historical

MongoDB advisories

Security and product notices from the vendor feed - scan the last seven days or browse the full set. Refine by cloud, timeframe, and search.

Updated about 2 hours ago

Advisories

Advisories

Showing 25 of 26 advisories
Jul 22, 2026, 03:23 PM EDT
Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow (CVE-2026-14881)
Jul 22, 2026, 03:22 PM EDT
Server crash via aggregation pipeline expression with compound wildcard index specification (CVE-2026-13055)
Jul 22, 2026, 03:22 PM EDT
A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM (CVE-2026-13056)
Jul 22, 2026, 03:22 PM EDT
Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $SEARCH_META (CVE-2026-13057)
Jul 22, 2026, 03:21 PM EDT
Transaction Command Insufficient Input Validation Leading to Process Termination (CVE-2026-13058)
Jul 22, 2026, 03:21 PM EDT
Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass (CVE-2026-13059)
Jul 22, 2026, 03:20 PM EDT
Find command with $meta sort can lead to crash (CVE-2026-9737)
Jul 22, 2026, 03:19 PM EDT
$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access (CVE-2026-13060)
Jul 22, 2026, 03:19 PM EDT
Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage (CVE-2026-13061)
Jul 22, 2026, 03:19 PM EDT
MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters (CVE-2026-13062)
Jul 22, 2026, 03:18 PM EDT
libmongocrypt Improper Input Validation Leading to Process Termination (CVE-2026-13063)
Jul 22, 2026, 03:17 PM EDT
MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service (CVE-2026-13064)
Jul 22, 2026, 03:17 PM EDT
MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination (CVE-2026-13065)
Jul 22, 2026, 03:17 PM EDT
Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure (CVE-2026-13066)
Jul 22, 2026, 03:16 PM EDT
tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket (CVE-2026-13067)
Jul 22, 2026, 03:16 PM EDT
MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse (CVE-2026-13068)
Jul 22, 2026, 03:15 PM EDT
Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion (CVE-2026-13069)
Jul 22, 2026, 03:15 PM EDT
Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination (CVE-2026-13070)
Jul 22, 2026, 03:14 PM EDT
Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termination (CVE-2026-13071)
Jul 22, 2026, 03:14 PM EDT
MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption (CVE-2026-13072)
Jul 22, 2026, 03:13 PM EDT
MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination (CVE-2026-13073)
Jul 22, 2026, 03:13 PM EDT
Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service (CVE-2026-13074)
Jul 22, 2026, 03:13 PM EDT
$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation (CVE-2026-13075)
Jul 22, 2026, 03:12 PM EDT
Aggregation Framework Memory Exhaustion Leading to Process Termination (CVE-2026-13076)
Jul 22, 2026, 03:12 PM EDT
Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data (CVE-2026-13077)

Data access

Unlock more advisories for MongoDB

You're seeing 26 advisories from the last 7 days without signing in.

Public session

Public

Next step: Free - 7 days history and full feed tools. No card required to start.

What you can unlock

Higher tiers unlock more history and more rows.

  • Recommended next step

    Free

    Same 7 days window ยท adds plan perks

    • Incidents, maintenance, updates, and advisories
    • Unlimited vendor monitoring
    • Analytics and trends
    Alerts

    Plan perks

  • Standard

    30 days history

    • Everything in Free
    • Analytics
    • Compliance snapshots
    Alerts

    Wider window

  • Pro

    90 days history

    • Everything in Standard
    • Analytics
    • REST API

    Wider window