// OSSeva Blog
SecurityMongoDB Vulnerabilities by Version: CVEs for MongoDB 4.4, 5.0, 6.0, 7.0 and 8.x
The short answer
MongoDB supports four server lines today: 9.0, released in September 2026 and supported until 31 October 2031, 8.3 and 8.0 until 31 October 2029, and 7.0 until 31 August 2027. 8.2 reached end of life on 31 July 2026, 6.0 on 31 July 2025, 5.0 on 31 October 2024, 4.4 on 29 February 2024 and 4.2 on 30 April 2023. MongoDB's alerts page lists 112 MongoDB Server alerts published in 2026. Only two of them name 6.0 or older, and for those two MongoDB shipped releases on lines past end of life: 6.0.28 and 6.0.29, 5.0.33 and 5.0.34, and 4.4.31. The other 110 list only 7.0 and later, so 6.0 and older were not assessed for them.
MongoDB release lines and their CVEs
End-of-life dates are from MongoDB's software lifecycle schedules, and release versions and dates from MongoDB's download list. The counts are the 2026 alerts on mongodb.com/resources/products/alerts that list each line.
| Line | Status | Latest release | 2026 server alerts naming it | Upstream fix on this line |
|---|---|---|---|---|
| 9.0 | Supported until 31 October 2031 | 9.0.2, 17 September 2026 | None so far | Not applicable |
| 8.3 | Supported until 31 October 2029 | 8.3.11, 3 September 2026 | 92 | All 92, by 8.3.11 |
| 8.2 | End of life 31 July 2026 | 8.2.12, 26 June 2026 | 54 | All 54, by 8.2.12; alerts since then do not list 8.2 |
| 8.0 | Supported until 31 October 2029 | 8.0.32, 3 September 2026 | 92 | All 92, by 8.0.32 |
| 7.0 | Supported until 31 August 2027 | 7.0.43, 3 September 2026 | 82 | All 82, by 7.0.43 |
| 6.0 | End of life 31 July 2025 | 6.0.29, 10 June 2026 | 2 | Both, in 6.0.28 and 6.0.29 |
| 5.0 | End of life 31 October 2024 | 5.0.34, 10 June 2026 | 2 | Both, in 5.0.33 and 5.0.34 |
| 4.4 | End of life 29 February 2024 | 4.4.31, 10 June 2026 | 1 | 4.4.31; CVE-2026-8053 does not list 4.4 |
| 4.2 | End of life 30 April 2023 | 4.2.25, 16 October 2023 | None; CVE-2025-14847 from December 2025 names it | No upstream fix on this line |
| 4.0 and 3.6 | End of life 30 April 2022 and 30 April 2021 | 4.0.28; 3.6.23 | None; CVE-2025-14847 names them | No upstream fix on these lines |
MongoDB's support policy carries no obligation to support a version past its end-of-life date, so the post-EOL releases for 4.4 to 6.0 were MongoDB's choice in each case. 74 of the 2026 alerts came out after 12 June, and none of them lists 6.0, 5.0 or 4.4. MongoDB's tickets for two of the August and September CVEs list an 8.2.13 fix, but no 8.2 release after 8.2.12 is on the download list. See the MongoDB end of life tracker for every line.
Notable MongoDB CVEs by release line
CVSS is NVD's own CVSS 3.1 score where NVD has scored the record, otherwise MongoDB's CVSS 3.1 score as the CNA. MongoDB's alerts page shows CVSS 4.0 scores, which often differ. One MongoDB Server CVE is in CISA's Known Exploited Vulnerabilities catalogue: CVE-2025-14847, added on 29 December 2025.
| CVE | Issue | CVSS | Fixed in | Lines with no fix |
|---|---|---|---|---|
| CVE-2025-14847 | Mismatched length fields in zlib-compressed messages let an unauthenticated client read uninitialised heap memory | 7.5 (MongoDB) | 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, 4.4.30 | 4.2, 4.0, 3.6 |
| CVE-2024-1351 | A server started with TLS and no CA file skips peer certificate validation on incoming connections | 9.8 (NVD) | 7.0.6, 6.0.14, 5.0.25, 4.4.29 | 4.2 and older not listed |
| CVE-2025-3085 | On Linux with CRL checking enabled, intermediate certificates are not checked for revocation, which can affect X.509 authentication | 9.8 (NVD) | 8.0.4, 7.0.16, 6.0.20, 5.0.31 | 4.4 and older not listed |
| CVE-2026-11933 | Use after free in server-side JavaScript, reachable through $where or $function, can leak process memory or crash mongod | 8.8 (NVD) | 8.3.4, 8.2.12, 8.0.26, 7.0.37, 6.0.29, 5.0.34, 4.4.31 | 4.2 and older not listed |
| CVE-2026-8053 | Duplicate field names in time-series inserts cause an out-of-bounds write that can lead to code execution | 8.8 (MongoDB) | 8.3.2, 8.2.9, 8.0.23, 7.0.34, 6.0.28, 5.0.33 | 4.4 and older not listed |
| CVE-2026-18691 | A party on the network can steer intra-cluster authentication so the shared internal credential can be recovered | 8.8 (MongoDB) | 8.3.8, 8.0.29, 7.0.40 | 8.2 and 6.0 and older not listed |
| CVE-2024-10921 | Crafted requests that build malformed BSON crash the server or return over-read memory | 8.1 (NVD) | 8.0.3, 7.0.15, 6.0.19, 5.0.30 | 4.4 and older not listed |
| CVE-2026-82067 | Case handling in configuration validation can leave authorization disabled at startup, open to unauthenticated admin operations | 8.1 (MongoDB) | 8.3.9, 8.0.30, 7.0.41 | 8.2 and 6.0 and older not listed |
| CVE-2026-13072 | Memory corruption in aggregation with the non-default compute mode on a standalone mongod | 8.1 (MongoDB) | 8.3.7, 8.2.12, 8.0.28, 7.0.39 | 6.0 and older not listed |
| CVE-2026-9740 | Unbounded recursion in BSON validation lets an unauthenticated client crash mongod | 7.5 (MongoDB) | 8.3.3, 8.2.10, 8.0.24, 7.0.35 | 6.0 and older not listed |
| CVE-2026-25611 | Crafted unauthenticated messages exhaust memory and crash the server | 7.5 (MongoDB) | 8.2.4, 8.0.18, 7.0.29 | 6.0 and older not listed |
| CVE-2026-82064 | An unauthenticated read concern request terminates certain replica set members | 7.5 (MongoDB) | 8.3.9, 8.0.30, 7.0.41 | 8.2 and 6.0 and older not listed |
| CVE-2025-6710 | Deeply nested JSON overflows the stack, before authentication on 7.0 and 8.0 | 7.5 (MongoDB) | 8.0.5, 7.0.17, 6.0.21 | 5.0 and older not listed |
Three groups stand out. CVE-2025-14847, CVE-2026-9740, CVE-2026-25611 and CVE-2026-82064 need no login at all, so any mongod or mongos port reachable from an untrusted network is exposed. CVE-2024-1351, CVE-2025-3085 and CVE-2026-18691 weaken TLS and intra-cluster authentication, which matters most where replica set members talk across networks you do not control. CVE-2026-11933 and CVE-2026-8053 need a login with read or write access, which in many estates means every application account.
What each line gets
MongoDB 7.0, 8.0, 8.3 and 9.0
These lines are supported, and 7.0.43, 8.0.32 and 8.3.11 carry every 2026 fix that names them. 7.0 is the next to reach end of life, on 31 August 2027. Moving from 7.0 to 8.0 is one major upgrade with a featureCompatibilityVersion change. See MongoDB 7.0 end of life.
MongoDB 8.2
8.2 had a short life: it ended on 31 July 2026, and 8.2.12 is the last public release. It has every fix that lists 8.2, but alerts published since August, including CVE-2026-18691 and CVE-2026-82067, leave it out. Moving to 8.3, which is supported until 31 October 2029, is the short step.
MongoDB 6.0 and 5.0
6.0.29 and 5.0.34 fix MongoBleed and the two 2026 CVEs that name them, so a server on an older 6.0 or 5.0 patch release should move to those first. They do not have fixes for the 2025 and 2026 CVEs that list only 7.0 and later, such as the unauthenticated crashes CVE-2026-9740 and CVE-2026-25611, because MongoDB did not assess these lines for them. 5.0 and later need AVX on x86_64. See MongoDB 6.0 end of life and MongoDB 5.0 end of life.
MongoDB 4.4
4.4 is the last line that runs on x86_64 CPUs without AVX, which is why so many deployments stay on it. 4.4.30 and 4.4.31 fixed CVE-2025-14847 and CVE-2026-11933, but 4.4 is not listed for CVE-2026-8053, CVE-2025-3085, CVE-2024-10921 or anything after June 2026. See MongoDB 4.4 end of life and MongoDB's AVX requirement.
MongoDB 4.2 and older
4.2.25 from October 2023 is the last 4.2 release, and MongoDB shipped no fix for CVE-2025-14847 on 4.2, 4.0 or 3.6, although CISA lists it as exploited. Disabling zlib compression is the only upstream mitigation on these lines.
What to do on each line
- 7.0, 8.0 and 8.3. Stay on the latest patch release.
- 8.2. Move to 8.3.11.
- 6.0 and 5.0. Move to 6.0.29 or 5.0.34 now, then plan the upgrade to 7.0 or 8.0, one major version at a time, or take patched builds.
- 4.4 and older. Move 4.4 to 4.4.31. On every line, start mongod and mongos with networkMessageCompressors or net.compression.compressors set to snappy,zstd or disabled to remove zlib, require a CA file whenever TLS is on, keep server ports off untrusted networks, and turn off server-side JavaScript with security.javascriptEnabled: false if your applications do not use it.
For the upgrade path itself, see upgrading MongoDB 4.4, 5.0 or 6.0 to 7.0 or 8.0.
Where OSSeva fits
OSSeva ships patched builds of self-managed MongoDB 4.2, 4.4, 5.0 and 6.0, including 4.2 and 4.4 builds for hardware without AVX. OSSeva backports fixes of this class to the end-of-life release lines it patches, covering mongod, mongos and the bundled tools, and delivers them as signed packages and container images with SBOMs. They are available now on the Patch, Assure and Operate tiers. Assure adds an authentication, TLS and network exposure review, a featureCompatibilityVersion upgrade plan and a driver compatibility audit, and Operate adds 24/7 replica set and cluster monitoring with a 15-minute P1 response and a named MongoDB engineer. See MongoDB extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.