MongoDB Vulnerabilities and Affected Products
Vulnerabilities associated with BSON::XS.
Products
Clear product- MongoDB Server65 vulnerabilities
- mongodb9 vulnerabilities
- BI Connector ODBC Driver6 vulnerabilities
- Atlas SQL ODBC Driver2 vulnerabilities
- Schema Builder CLI2 vulnerabilities
- BSON::XS1 vulnerability
- C Driver1 vulnerability
- c\#_driver1 vulnerability
- c_driver1 vulnerability
- java_driver1 vulnerability
- Mongo-c-driver1 vulnerability
- mongo-express1 vulnerability
- MongoDB and MongoDB Server1 vulnerability
- MongoDB Compass1 vulnerability
- MongoDB Driver1 vulnerability
- mongodb_server1 vulnerability
- PHP Driver1 vulnerability
- Rust Driver1 vulnerability
- rust_driver1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-40906CRITICAL | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported. | CVSS9.8v3.1 | EPSS0.567% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |