MongoDB vulnerabilities
35 CVEs tracked
MongoDB appears in recent reporting with multiple critical vulnerabilities disclosed. The primary themes involve denial-of-service (DoS) attacks exploitable by authenticated users, internal memory leaks, and resource exhaustion. Key CVEs include CVE-2026-13055 (server crash via `$_internalIndexKey` expression), CVE-2026-13063 (memory exhaustion causing process termination), CVE-2026-13078 (arbitrary file reading), and the unauthenticated CPU exhaustion issue CVE-2026-13074. Defenders should focus on proper authorization configurations, network-level access controls, and the immediate application of security patches to mitigate the exploitation of these vulnerabilities.
Azərbaycanca: MongoDB hesabat dövründə bir sıra kritik zəifliklərlə bağlı xəbərdarlıqlarda yer alır. Əsas mövzular autentifikasiya olunmuş istifadəçilər tərəfindən törədilə bilən xidmətin dayandırılması (DoS) hücumları, server yaddaşının sızması və resurs tükənməsi ilə bağlıdır. Bunlara CVE-2026-13055 (`$_internalIndexKey` ifadəsi ilə serverin çökməsi), CVE-2026-13063 (yaddaşın tükənməsi ilə prosesin dayandırılması), CVE-2026-13078 (ixtiyari faylların oxunması) və autentifikasiya olunmamış şəkildə CPU resurslarını tükədə bilən CVE-2026-13074 daxildir. Müdafiəçilər xüsusilə avtorizasiya mexanizmlərinin düzgün konfiqurasiyasına, şəbəkə səviyyəsində giriş nəzarətinə və bu zəifliklərin istismarını məhdudlaşdırmaq üçün dərhal təhlükəsizlik yeniləmələrinin tətbiqinə diqqət yetirməlidir.
This vendor's CVEs35
- CVE-2026-19003EPSS 0.14%
- CVE-2026-18712EPSS 0.18%
- CVE-2026-18711EPSS 0.27%
- CVE-2026-18710EPSS 0.12%
- CVE-2026-18709EPSS 0.14%
- CVE-2026-18708EPSS 0.28%
- CVE-2026-18707EPSS 0.26%
- CVE-2026-18706EPSS 0.34%
- CVE-2026-18705EPSS 0.27%
- CVE-2026-18704EPSS 0.21%
- CVE-2026-18703EPSS 0.11%
- CVE-2026-18702EPSS 0.21%
- CVE-2026-18701EPSS 0.30%
- CVE-2026-18700EPSS 0.29%
- CVE-2026-18699EPSS 0.29%
- CVE-2026-18698EPSS 0.17%
- CVE-2026-18697EPSS 0.35%
- CVE-2026-18696EPSS 0.29%
- CVE-2026-18695EPSS 0.29%
- CVE-2026-18694EPSS 0.27%
- CVE-2026-18693EPSS 0.23%
- CVE-2026-18692EPSS 0.43%
- CVE-2026-18691EPSS 0.24%
- CVE-2026-18690EPSS 0.27%
- CVE-2026-18688EPSS 0.27%
- CVE-2026-18687EPSS 0.17%
- CVE-2026-13078EPSS 0.34%
- CVE-2026-13076EPSS 0.42%
- CVE-2026-13074EPSS 0.29%
- CVE-2026-13070EPSS 0.13%
- CVE-2026-13069EPSS 0.17%
- CVE-2026-13066EPSS 0.37%
- CVE-2026-13064EPSS 0.45%
- CVE-2026-13063EPSS 0.23%
- CVE-2026-13055EPSS 0.28%
This hub is built from skopnix's own reporting on MongoDB: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.