Search CVE reports


Toggle filters

1 – 10 of 1786 results


CVE-2026-32710

Medium priority
Needs evaluation

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might...

1 affected package

mariadb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb Needs evaluation Not in release
Show less packages

CVE-2026-4358

Medium priority
Needs evaluation

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-4148

Medium priority
Needs evaluation

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-4147

Medium priority
Needs evaluation

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-25613

Medium priority
Vulnerable

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2026-25610

Medium priority
Vulnerable

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2026-25609

Medium priority
Not affected

Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-1850

Medium priority
Not affected

Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-1849

Medium priority
Vulnerable

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2026-1848

Medium priority
Not affected

Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages