Search CVE reports


Toggle filters

1 – 10 of 1787 results


CVE-2026-5170

Medium priority
Needs evaluation

(A user with access to the cluster with a limited set of privilege acti ...)

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-32710

Medium priority
Needs evaluation

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might...

1 affected package

mariadb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb Needs evaluation Not in release
Show less packages

CVE-2026-4358

Medium priority
Needs evaluation

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-4148

Medium priority
Needs evaluation

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-4147

Medium priority
Needs evaluation

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-25613

Medium priority
Vulnerable

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2026-25610

Medium priority
Vulnerable

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2026-25609

Medium priority
Not affected

Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-1850

Medium priority
Not affected

Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-1849

Medium priority
Vulnerable

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages