EventJoin us at AWS re:Invent 2024! Learn how to use MongoDB for AI use cases. Learn more >>

MongoDB Security Bulletins

Stay informed with the latest CVEs, security incident updates and answers to your key questions on MongoDB’s comprehensive Security Bulletins page.

Common Vulnerabilities and Exposures (CVEs)

11/14/2024
CVE-2024-10921
6.8

Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server

An authorized user may trigger crashes or receive the contents of buffer over-reads of Ser...

Affects:

MongoDB Server

Versions:

5.0 affects versions prior to 5.0.30
6.0 affects versions prior to 6.0.19
7.0 affects versions prior to 7.0.15
8.0 affects versions prior to 8.0.3

10/28/2024
CVE-2024-8013
2.2

CSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelines

A bug in query analysis of certain complex self-referential $lookup subpipelines may resul...

Affects:

mongocryptd

Versions:

5.0 affects versions prior to 5.0.29
6.0 affects versions prior to 6.0.17
7.0 affects versions prior to 7.012
7.3 affects versions prior to 7.3.4

Affects:

Mongo_crypt_v1.so

Versions:

6.0 affects versions prior to 6.0.17
7.0 affects versions prior to 7.0.12
7.3 affects versions prior to 7.3.4

10/21/2024
CVE-2024-8305
6.5

MongoDB Server secondaries may crash due to forced index constraints

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index c...

Affects:

MongoDB Server

Versions:

6.0 affects versions prior to 6.0.17
7.0 affects versions prior to 7.0.13
7.3 affects versions prior to 7.3.4

09/10/2024
CVE-2024-8654
5

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour...

Affects:

MongoDB Server

Versions:

6.0.3

08/27/2024
CVE-2024-8207
6.4

MongoDB Server binaries may load potentially insecure shared libraries from specific relative paths

In certain highly specific configurations of the host system and MongoDB server binary ins...

Affects:

MongoDB Server

Versions:

6.0 affects versions prior to 6.0.3
5.0 affects versions prior to 5.0.14

08/13/2024
CVE-2024-6384
5.3

Backup files may be downloaded by underprivileged users in MongoDB Enterprise Server

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acqu...

Affects:

MongoDB Server

Versions:

6.0 affects versions prior to 6.0.16
7.0 affects versions prior to 7.0.11
7.3 affects versions prior to 7.3.3

08/07/2024
CVE-2024-7553
7.3

Accessing Untrusted Directory May Allow Local Privilege Escalation

Incorrect validation of files loaded from a local untrusted directory may allow local priv...

Affects:

MongoDB Server

Versions:

5.0 affects versions prior to 5.0.27
6.0 affects versions prior to 6.0.16
7.0 affects versions prior to 7.0.12
7.3 affects versions prior to 7.3.3

Affects:

MongoDB C Driver

Versions:

affects versions prior to 1.26.2

Affects:

MongoDB PHP Driver

Versions:

affects versions prior to 1.18.1

07/03/2024
CVE-2024-6383
5.3

MongoDB C Driver bson_string_append may be vulnerable to a buffer overflow

The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow...

Affects:

libbson

Versions:

0 affects versions prior to 1.27.1

07/02/2024
CVE-2024-6382
6.4

Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing...

Affects:

MongoDB Rust Driver

Versions:

2.0 affects versions prior to 2.8.2

07/02/2024
CVE-2024-6381
4

MongoDB C Driver bson_strfreev may be susceptible to integer overflow

The bson_strfreev function in the MongoDB C driver library may be susceptible to an intege...

Affects:

libbson

Versions:

affects versions prior to 1.26.2

07/01/2024
CVE-2024-6376
7

ejson shell parser in MongoDB Compass maybe bypassed

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protectio...

Affects:

MongoDB Compass

Versions:

affects versions prior to 1.42.2

07/01/2024
CVE-2024-6375
5.4

Missing authorization check may lead to shard key refinement

A command for refining a collection shard key is missing an authorization check. This may ...

Affects:

MongoDB Server

Versions:

5.0 affects versions prior to 5.0.22
6.0 affects versions prior to 6.0.11
7.0 affects versions prior to 7.0.3

06/05/2024
CVE-2024-5629
4.7

Out-of-bounds read in bson module of PyMongo

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserializat...

Affects:

PyMongo

Versions:

affects 4.6.2 and prior versions

05/14/2024
CVE-2024-3374
5.3

MongoDB Server (mongod) may crash when generating ftdc

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc ...

Affects:

MongoDB Server

Versions:

5.0 affects 5.0.16 and prior versions
6.0 affects 6.0.5 and prior versions

05/14/2024
CVE-2024-3372
7.5

MongoDB Server may have unexpected application behaviour due to invalid BSON

Improper validation of certain metadata input may result in the server not correctly seria...

Affects:

MongoDB Server

Versions:

5.0 affects versions prior to 5.0.25
6.0 affects versions prior to 6.0.14
7.0 affects versions prior to 7.0.6

04/24/2024
CVE-2024-3371
7.1

Insufficient validation of external input in Compass may enable MITM attacks

MongoDB Compass may accept and use insufficiently validated input from an untrusted extern...

Affects:

MongoDB Compass

Versions:

affects 1.35.0 to 1.42.0

03/07/2024
CVE-2024-1351
8.8

MongoDB Server may allow successful untrusted connection

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer c...

Affects:

MongoDB Server

versions:

7.0 affects 7.0.5 and prior versions
6.0 affects 6.0.13 and prior versions
5.0 affects 5.0.24 and prior versions
4.4 affects 4.4.28 and prior versions

01/12/2024
CVE-2023-0437
5.3

MongoDB client C Driver may infinitely loop when validating certain BSON input data

When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot b...

Affects:

MongoDB C Driver

versions:

1.0.0 affects versions prior to 1.25.0

11/07/2023
CVE-2023-0436
4.5

Secret logging may occur in debug mode of Atlas Operator

The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information...

Affects:

MongoDB Atlas Kubernetes Operator

versions:

1.5.0 affects 1.7.0 and prior versions

08/29/2023
CVE-2021-32050
4.2

Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application

Some MongoDB Drivers may erroneously publish events containing authentication-related data...

Affects:

MongoDB C Driver

Versions:

1.0.0 affects versions prior to 1.17.7

Affects:

MongoDB C++ Driver

Versions:

3.0.0 affects versions prior to 3.7.0

Affects:

MongoDB PHP Driver

Versions:

1.0.0 affects versions prior to 1.9.2

Affects:

MongoDB Swift Driver

Versions:

1.0.0 affects versions prior to 1.1.1

Affects:

MongoDB Node.js Driver

Versions:

3.6 affects versions prior to 3.6.10
4.0 affects versions prior to 4.17.0
5.0 affects versions prior to 5.8.0

08/23/2023
CVE-2023-1409
5.3

Certificate validation issue in MongoDB Server running on Windows or macOS

If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific...

Affects:

MongoDB Server

versions:

6.3 affects 6.3.2 and prior versions
5.0 affects 5.0.14 and prior versions
4.4 affects 4.4.23 and prior versions

08/08/2023
CVE-2023-4009
7.2

Privilege Escalation for Project Owner and Project User Admin Roles in Ops Manager

In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an...

Affects:

MongoDB Ops Manager

versions:

6.0 affects versions prior to 6.0.17
5.0 affects versions prior to 5.0.22

06/09/2023
CVE-2023-0342
3.1

MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive

MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app...

Affects:

MongoDB Ops Manager

versions:

v5.0 affects versions prior to 5.0.21
v6.0 affects versions prior to 6.0.12

02/21/2023
CVE-2022-48282
6.6

Deserializing compromised object with MongoDB .NET/C# Driver may cause remote code execution

Under very specific circumstances (see Required configuration section below), a privileged...

Affects:

MongoDB .NET/C# Driver

versions:

0 affects v2.18.0 and prior versions

05/11/2022
CVE-2022-24272
6.5

MongoDB Server (mongod) may crash in response to unexpected requests

An authenticated user may trigger an invariant assertion during command dispatch due to in...

Affects:

MongoDB Server

versions:

5.0 affects 5.0.6 and prior versions

04/12/2022
CVE-2021-32040
6.5

Large aggregation pipelines with a specific stage can crash mongod under default configuration

It may be possible to have an extremely long aggregation pipeline in conjunction with a sp...

Affects:

MongoDB Server

versions:

5.0 affects versions prior to 5.0.4
4.4 affects versions prior to 4.4.11
4.2 affects versions prior to 4.2.16

02/04/2022
CVE-2021-32036
5.4

Denial of Service and Data Integrity vulnerability in features command

An authenticated user without any specific authorizations may be able to repeatedly invoke...

Affects:

MongoDB Server

versions:

5.0 affects 5.0.3 and prior versions
4.4 affects 4.4.9 and prior versions
4.2 affects 4.2.16 and prior versions
4.0 affects 4.0.28 and prior versions

01/20/2022
CVE-2021-32039
5.5

MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text

Users with appropriate file access may be able to access unencrypted user credentials save...

Affects:

MongoDB for VS Code

versions:

MongoDB for VS Code affects 0.7.0 and prior versions

12/15/2021
CVE-2021-20330
6.5

Specific replication command with malformed oplog entries can crash secondaries

An attacker with basic CRUD permissions on a replicated collection can run the applyOps co...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.27
4.2 affects versions prior to 4.2.16
4.4 affects versions prior to 4.4.9

11/24/2021
CVE-2021-32037
6.5

User may trigger invariant when allowed to send commands directly to shards

An authorized user may trigger an invariant which may result in denial of service or serve...

Affects:

MongoDB Server

versions:

5.0 affects 5.0.2 and prior versions

08/02/2021
CVE-2021-20332
4.2

MongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an application

Specific MongoDB Rust Driver versions can include credentials used by the connection pool ...

Affects:

MongoDB Rust Driver

versions:

2.0.0-alpha
2.0.0-alpha1
1.0.0 affects 1.2.1 and prior versions

07/23/2021
CVE-2021-20333
5.3

Server log entry spoofing via newline injection

Sending specially crafted commands to a MongoDB Server may result in artificial log entrie...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.20
4.0 affects versions prior to 4.0.21
4.2 affects versions prior to 4.2.10

06/10/2021
CVE-2021-20329
6.8

Specific cstrings input may not be properly validated in the Go Driver

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marsha...

Affects:

MongoDB Go Driver

versions:

1.0 affects 1.5.0 and prior versions

05/24/2021
CVE-2021-20331
4.2

MongoDB C# Driver may publish events containing authentication-related data to a command listener configured by an application

Specific versions of the MongoDB C# Driver may erroneously publish events containing authe...

Affects:

MongoDB C# Driver

versions:

2.12 affects 2.12.1 and prior versions

04/30/2021
CVE-2021-20326
6.5

Specially crafted query may result in a denial of service of mongod

A user authorized to performing a specific type of find query may trigger a denial of serv...

Affects:

MongoDB Server

versions:

4.4 affects versions prior to 4.4.4

04/12/2021
CVE-2020-7924
4.2

Specific command line parameter might result in accepting invalid certificate

Usage of specific command line parameter in MongoDB Tools which was originally intended to...

Affects:

MongoDB Database Tools

versions:

3.6.5 affects versions prior to 3.6*
4.0 affects versions prior to 4.0.21
4.2 affects versions prior to 4.2.11
100 affects versions prior to 100.2.0

04/06/2021
CVE-2021-20334
4.8

Local privilege escalation in MongoDB Compass for Windows

A malicious 3rd party with local access to the Windows machine where MongoDB Compass is in...

Affects:

MongoDB Compass

versions:

1.3.0 affects versions prior to 1.x*

02/26/2021
CVE-2020-7929
6.5

Specially crafted regex query can cause DoS

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.21
4.0 affects versions prior to 4.0.20

02/26/2021
CVE-2018-25004
4.9

Invariant failure when explaining a find with a UUID

A user authorized to performing a specific type of query may trigger a denial of service b...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.11
4.0 affects versions prior to 4.0.6

02/25/2021
CVE-2021-20327
6.4

MongoDB Node.js client side field level encryption library may not be validating KMS certificate

A specific version of the Node.js mongodb-client-encryption module does not perform correc...

Affects:

mongodb-client-encryption module

versions:

1.2.0

02/25/2021
CVE-2021-20328
6.4

MongoDB Java driver client-side field level encryption not verifying KMS host name

Specific versions of the Java driver that support client-side field level encryption (CSFL...

Affects:

mongo-java-driver

versions:

3.11 affects 3.11.2 and prior versions
3.12 affects 3.12.7 and prior versions

02/11/2021
CVE-2021-20335
6.7

SSL may be unexpectedly disabled during upgrade of multiple-server MongoDB Ops Manager

For MongoDB Ops Manager <= 4.2.24 with multiple OM application servers, that have SSL turn...

Affects:

Ops Manager

versions:

4.2 affects 4.2.24 and prior versions

12/01/2020
CVE-2019-20924
6.5

Invariant in IndexBoundsBuilder

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

4.2 affects versions prior to 4.2.2

11/30/2020
CVE-2020-7925
7.5

Denial of Service when processing malformed Role names

Incorrect validation of user input in the role name parser may lead to use of uninitialize...

Affects:

MongoDB Server

versions:

4.2 affects versions prior to 4.2.9
4.4 affects versions prior to 4.4.0-rc12

11/30/2020
CVE-2020-7926
6.5

Specific query can cause a DoS against MongoDB Server

A user authorized to perform database queries may cause denial of service by issuing a spe...

Affects:

MongoDB Server

versions:

4.4 affects versions prior to 4.4.1

11/30/2020
CVE-2020-7927
8.1

Potential privilege escalation in Ops Manager API

Specially crafted API calls may allow an authenticated user who holds Organization Owner p...

Affects:

MongoDB Ops Manager

versions:

4.2 affects 4.2.17 and prior versions
4.3 affects 4.3.9 and prior versions
4.4 affects 4.4.2 and prior versions

11/30/2020
CVE-2019-2392
6.5

$mod can result in UB

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.20
4.0 affects versions prior to 4.0.20
4.2 affects versions prior to 4.2.9
4.4 affects versions prior to 4.4.1

11/30/2020
CVE-2019-2393
6.5

Crash while joining collections with $lookup

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.15
4.0 affects versions prior to 4.0.13
4.2 affects versions prior to 4.2.1

11/30/2020
CVE-2019-20923
6.5

Crash while handling internal Javascript exception types

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.7

11/30/2020
CVE-2018-20802
6.5

Post-auth queries on compound index may crash mongod

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.9
4.0 affects versions prior to 4.0.3

11/30/2020
CVE-2018-20804
6.5

Invariant failure in applyOps

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.13
4.0 affects versions prior to 4.0.10

11/30/2020
CVE-2018-20805
6.5

Invariant with $elemMatch

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

3.6 affects versions prior to 3.6.10
4.0 affects versions prior to 4.0.5

11/24/2020
CVE-2019-20925
7.5

Denial of service via malformed network packet

An unauthenticated client can trigger denial of service by issuing specially crafted wire ...

Affects:

MongoDB Server

versions:

4.2 affects versions prior to 4.2.1
4.0 affects versions prior to 4.0.13
3.6 affects versions prior to 3.6.15
3.4 affects versions prior to 3.4.24

11/23/2020
CVE-2020-7928
6.5

Improper neutralization of null byte leads to read overrun

A user authorized to perform database queries may trigger a read overrun and access arbitr...

Affects:

MongoDB Server

versions:

4.4 affects versions prior to 4.4.1
4.2 affects versions prior to 4.2.9
4.0 affects versions prior to 4.0.20
3.6 affects versions prior to 3.6.20

11/23/2020
CVE-2018-20803
6.5

Infinite loop in aggregation expression

A user authorized to perform database queries may trigger denial of service by issuing spe...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.5
3.6 affects versions prior to 3.6.10
3.4 affects versions prior to 3.4.19

08/21/2020
CVE-2020-7923
6.5

Specific GeoQuery can cause DoS against MongoDB Server

A user authorized to perform database queries may cause denial of service by issuing speci...

Affects:

MongoDB Server

versions:

4.4 affects versions prior to 4.4.0-rc7
4.2 affects versions prior to 4.2.8
4.0 affects versions prior to 4.0.19

05/13/2020
CVE-2019-2388
5.8

Potential exposure of log information in Ops Manager

In affected Ops Manager versions there is an exposed http route was that may allow attacke...

Affects:

Ops Manager

versions:

4.0.9
4.0.10
4.1.5

05/06/2020
CVE-2020-7921
4.6

Administrative action may disable enforcement of per-user IP whitelisting

Improper serialization of internal state in the authorization subsystem in MongoDB Server'...

Affects:

MongoDB Server

versions:

4.2 affects versions prior to 4.2.3
4.0 affects versions prior to 4.0.15
3.6 affects versions prior to 3.6.18
4.3 affects versions prior to 4.3.3

04/09/2020
CVE-2020-7922
6.4

Kubernetes Operator generates potentially insecure certificates

X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an at...

Affects:

MongoDB Enterprise Kubernetes Operator

versions:

1.0
1.1
1.2 affects 1.2.4 and prior versions
1.3 affects 1.3.1 and prior versions
1.4 affects 1.4.4 and prior versions

03/31/2020
CVE-2019-2391
4.2

JS-bson may incorrectly serialise some requests

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BS...

Affects:

js-bson

versions:

1.0 affects 1.1.3 and prior versions

08/30/2019
CVE-2019-2389
5.3

Process termination via PID file manipulation

Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow ...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.11
3.6 affects versions prior to 3.6.14
3.4 affects versions prior to 3.4.22

08/30/2019
CVE-2019-2390
8.2

Code execution on Windows via OpenSSL engine injection

An unprivileged user or program on Microsoft Windows which can create OpenSSL configuratio...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.11
3.6 affects versions prior to 3.6.14
3.4 affects versions prior to 3.4.22

08/06/2019
CVE-2019-2386
7.1

Authorization session conflation

After user deletion in MongoDB Server the improper invalidation of authorization sessions ...

Affects:

MongoDB Server

versions:

4.0 affects versions prior to 4.0.9
3.6 affects versions prior to 3.6.13
3.4 affects versions prior to 3.4.22