Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-9737: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9737
0

CVE-2026-9737 is a high-severity vulnerability in MongoDB Server involving a reachable assertion failure during query planning. The issue arises when the server reads the sort pattern in raw BSONObj form and does not properly handle the meta expression case, potentially causing an invariant failure. This vulnerability affects specific MongoDB Server versions 7.0, 8.0, 8.2.0, and 8.3.0. No official patch or remediation guidance has been provided yet, and there are no known exploits in the wild.

Join the discussion
CVE-2026-13078: CWE-862: Missing Authorization in MongoDB MongoDB ServerCVE-2026-13078
0

CVE-2026-13078 is a medium severity vulnerability in MongoDB Server where the server-side MozJS scripting engine registers a module loading hook that allows JavaScript code to read arbitrary files on the host filesystem with the privileges of the mongod process. An authenticated user can exploit this by sending crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process. No official patch or remediation guidance is currently provided.

Join the discussion
CVE-2026-13077: CWE-125: Out-of-bounds Read in MongoDB MongoDB ServerCVE-2026-13077
0

CVE-2026-13077 is a high-severity vulnerability in MongoDB Server involving a missing bounds check in BSON CodeWScope element accessors. An authenticated attacker can exploit this by crafting a malformed BSONColumn data containing a CodeWScope element, which bypasses wire-level BSON validation. This leads to an out-of-bounds heap read when the forged element is decompressed, potentially causing a server crash or disclosure of adjacent heap memory contents.

Join the discussion
CVE-2026-13076: CWE-770: Allocation of Resources Without Limits or Throttling in MongoDB MongoDB ServerCVE-2026-13076
0

CVE-2026-13076 is a high-severity vulnerability in MongoDB Server 8.3.0 where an authenticated user with write access can cause the mongod process to be terminated by the operating system due to excessive memory consumption. This occurs through a specific data type conversion operation within the aggregation framework, leading to resource exhaustion without limits or throttling.

Join the discussion
CVE-2026-13075: CWE-770: Allocation of Resources Without Limits or Throttling in MongoDB MongoDB ServerCVE-2026-13075
0

CVE-2026-13075 is a high-severity vulnerability in MongoDB Server versions 8.2.0 and 8.3.0. An authenticated user with the ability to run aggregation queries can cause the mongod process to be terminated by the operating system due to memory pressure triggered via the $rankFusion and $scoreFusion aggregation stages. The issue arises from the server's error-handling path and involves allocation of resources without limits or throttling.

Join the discussion
CVE-2026-13074: CWE-770: Allocation of Resources Without Limits or Throttling in MongoDB MongoDB ServerCVE-2026-13074
0

CVE-2026-13074 is a medium-severity vulnerability in MongoDB Server that allows an unauthenticated remote client to cause excessive CPU consumption. This occurs by sending a specific combination of parameters to the awaitable hello command in exhaust mode, which triggers a response loop bypassing normal throttling. This can degrade server availability with only a small number of connections. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-13073: CWE-617: Reachable Assertion in MongoDB MongoDB ServerCVE-2026-13073
0

CVE-2026-13073 is a medium severity vulnerability in MongoDB Server version 8.0 where an authenticated user with read-only privileges can cause the mongod process to crash by issuing a specially crafted aggregation command. This leads to a denial of service affecting all connected clients until the server process is restarted. The root cause is an internal engine selection inconsistency triggered by specific aggregation options.

Join the discussion
CVE-2026-13072: CWE-122: Heap-based Buffer Overflow in MongoDB MongoDB ServerCVE-2026-13072
0

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.

Join the discussion
CVE-2026-13071: CWE-416: Use After Faree in MongoDB MongoDB ServerCVE-2026-13071
0

CVE-2026-13071 is a high-severity use-after-free vulnerability in MongoDB Server that allows an authenticated user with read access to cause the mongod process to terminate. This occurs through certain aggregation expressions that execute server-side JavaScript, due to improper memory handling during document processing. The vulnerability affects specific MongoDB Server versions 7.0, 8.0, 8.2.0, and 8.3.0. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-13070: CWE-476: NULL Pointer Dereference in MongoDB MongoDB ServerCVE-2026-13070
0

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.

Join the discussion

Showing 1 to 10 of 24 results

Filters:Package: pkg:github/mongodb/mongo
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses