MongoDB Inc Vulnerabilities and Affected Products
Vulnerabilities associated with MongoDB C Driver.
Products
Clear product- MongoDB Server41 vulnerabilities
- MongoDB C Driver4 vulnerabilities
- mongosh4 vulnerabilities
- libbson3 vulnerabilities
- MongoDB Compass3 vulnerabilities
- MongoDB PHP Driver2 vulnerabilities
- Mongo_crypt_v1.so1 vulnerability
- mongocryptd1 vulnerability
- MongoDB .NET/C# Driver1 vulnerability
- MongoDB Atlas Kubernetes Operator1 vulnerability
- MongoDB C++ Driver1 vulnerability
- MongoDB Connector for BI1 vulnerability
- MongoDB Go Driver1 vulnerability
- MongoDB Node.js Driver1 vulnerability
- MongoDB Ruby Driver1 vulnerability
- MongoDB Rust Driver1 vulnerability
- MongoDB Swift Driver1 vulnerability
- PyMongo1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated bufferA compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver. CWE-158Mar 17, 2026 | CVSS2.0v4.0 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-7553HIGH | Accessing Untrusted Directory May Allow Local Privilege EscalationIncorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 versions prior to 7.0.12, MongoDB Server v7.3 versions prior 7.3.3, MongoDB C Driver versions prior to… CWE-284Aug 7, 2024 | CVSS7.3v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-0437MEDIUM | MongoDB client C Driver may infinitely loop when validating certain BSON input dataWhen calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0. CWE-835Jan 12, 2024 | CVSS5.3v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-32050MEDIUM | Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an applicationSome MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This … | CVSS4.2v3.1 | EPSS0.596% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |