Back to blog

// OSSeva Blog

Security

MongoDB Vulnerabilities by Version: CVEs for MongoDB 4.4, 5.0, 6.0, 7.0 and 8.x

Matt Reynolds9 min read

The short answer

MongoDB supports four server lines today: 9.0, released in September 2026 and supported until 31 October 2031, 8.3 and 8.0 until 31 October 2029, and 7.0 until 31 August 2027. 8.2 reached end of life on 31 July 2026, 6.0 on 31 July 2025, 5.0 on 31 October 2024, 4.4 on 29 February 2024 and 4.2 on 30 April 2023. MongoDB's alerts page lists 112 MongoDB Server alerts published in 2026. Only two of them name 6.0 or older, and for those two MongoDB shipped releases on lines past end of life: 6.0.28 and 6.0.29, 5.0.33 and 5.0.34, and 4.4.31. The other 110 list only 7.0 and later, so 6.0 and older were not assessed for them.

MongoDB release lines and their CVEs

End-of-life dates are from MongoDB's software lifecycle schedules, and release versions and dates from MongoDB's download list. The counts are the 2026 alerts on mongodb.com/resources/products/alerts that list each line.

LineStatusLatest release2026 server alerts naming itUpstream fix on this line
9.0Supported until 31 October 20319.0.2, 17 September 2026None so farNot applicable
8.3Supported until 31 October 20298.3.11, 3 September 202692All 92, by 8.3.11
8.2End of life 31 July 20268.2.12, 26 June 202654All 54, by 8.2.12; alerts since then do not list 8.2
8.0Supported until 31 October 20298.0.32, 3 September 202692All 92, by 8.0.32
7.0Supported until 31 August 20277.0.43, 3 September 202682All 82, by 7.0.43
6.0End of life 31 July 20256.0.29, 10 June 20262Both, in 6.0.28 and 6.0.29
5.0End of life 31 October 20245.0.34, 10 June 20262Both, in 5.0.33 and 5.0.34
4.4End of life 29 February 20244.4.31, 10 June 202614.4.31; CVE-2026-8053 does not list 4.4
4.2End of life 30 April 20234.2.25, 16 October 2023None; CVE-2025-14847 from December 2025 names itNo upstream fix on this line
4.0 and 3.6End of life 30 April 2022 and 30 April 20214.0.28; 3.6.23None; CVE-2025-14847 names themNo upstream fix on these lines

MongoDB's support policy carries no obligation to support a version past its end-of-life date, so the post-EOL releases for 4.4 to 6.0 were MongoDB's choice in each case. 74 of the 2026 alerts came out after 12 June, and none of them lists 6.0, 5.0 or 4.4. MongoDB's tickets for two of the August and September CVEs list an 8.2.13 fix, but no 8.2 release after 8.2.12 is on the download list. See the MongoDB end of life tracker for every line.

Notable MongoDB CVEs by release line

CVSS is NVD's own CVSS 3.1 score where NVD has scored the record, otherwise MongoDB's CVSS 3.1 score as the CNA. MongoDB's alerts page shows CVSS 4.0 scores, which often differ. One MongoDB Server CVE is in CISA's Known Exploited Vulnerabilities catalogue: CVE-2025-14847, added on 29 December 2025.

CVEIssueCVSSFixed inLines with no fix
CVE-2025-14847Mismatched length fields in zlib-compressed messages let an unauthenticated client read uninitialised heap memory7.5 (MongoDB)8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, 4.4.304.2, 4.0, 3.6
CVE-2024-1351A server started with TLS and no CA file skips peer certificate validation on incoming connections9.8 (NVD)7.0.6, 6.0.14, 5.0.25, 4.4.294.2 and older not listed
CVE-2025-3085On Linux with CRL checking enabled, intermediate certificates are not checked for revocation, which can affect X.509 authentication9.8 (NVD)8.0.4, 7.0.16, 6.0.20, 5.0.314.4 and older not listed
CVE-2026-11933Use after free in server-side JavaScript, reachable through $where or $function, can leak process memory or crash mongod8.8 (NVD)8.3.4, 8.2.12, 8.0.26, 7.0.37, 6.0.29, 5.0.34, 4.4.314.2 and older not listed
CVE-2026-8053Duplicate field names in time-series inserts cause an out-of-bounds write that can lead to code execution8.8 (MongoDB)8.3.2, 8.2.9, 8.0.23, 7.0.34, 6.0.28, 5.0.334.4 and older not listed
CVE-2026-18691A party on the network can steer intra-cluster authentication so the shared internal credential can be recovered8.8 (MongoDB)8.3.8, 8.0.29, 7.0.408.2 and 6.0 and older not listed
CVE-2024-10921Crafted requests that build malformed BSON crash the server or return over-read memory8.1 (NVD)8.0.3, 7.0.15, 6.0.19, 5.0.304.4 and older not listed
CVE-2026-82067Case handling in configuration validation can leave authorization disabled at startup, open to unauthenticated admin operations8.1 (MongoDB)8.3.9, 8.0.30, 7.0.418.2 and 6.0 and older not listed
CVE-2026-13072Memory corruption in aggregation with the non-default compute mode on a standalone mongod8.1 (MongoDB)8.3.7, 8.2.12, 8.0.28, 7.0.396.0 and older not listed
CVE-2026-9740Unbounded recursion in BSON validation lets an unauthenticated client crash mongod7.5 (MongoDB)8.3.3, 8.2.10, 8.0.24, 7.0.356.0 and older not listed
CVE-2026-25611Crafted unauthenticated messages exhaust memory and crash the server7.5 (MongoDB)8.2.4, 8.0.18, 7.0.296.0 and older not listed
CVE-2026-82064An unauthenticated read concern request terminates certain replica set members7.5 (MongoDB)8.3.9, 8.0.30, 7.0.418.2 and 6.0 and older not listed
CVE-2025-6710Deeply nested JSON overflows the stack, before authentication on 7.0 and 8.07.5 (MongoDB)8.0.5, 7.0.17, 6.0.215.0 and older not listed

Three groups stand out. CVE-2025-14847, CVE-2026-9740, CVE-2026-25611 and CVE-2026-82064 need no login at all, so any mongod or mongos port reachable from an untrusted network is exposed. CVE-2024-1351, CVE-2025-3085 and CVE-2026-18691 weaken TLS and intra-cluster authentication, which matters most where replica set members talk across networks you do not control. CVE-2026-11933 and CVE-2026-8053 need a login with read or write access, which in many estates means every application account.

What each line gets

MongoDB 7.0, 8.0, 8.3 and 9.0

These lines are supported, and 7.0.43, 8.0.32 and 8.3.11 carry every 2026 fix that names them. 7.0 is the next to reach end of life, on 31 August 2027. Moving from 7.0 to 8.0 is one major upgrade with a featureCompatibilityVersion change. See MongoDB 7.0 end of life.

MongoDB 8.2

8.2 had a short life: it ended on 31 July 2026, and 8.2.12 is the last public release. It has every fix that lists 8.2, but alerts published since August, including CVE-2026-18691 and CVE-2026-82067, leave it out. Moving to 8.3, which is supported until 31 October 2029, is the short step.

MongoDB 6.0 and 5.0

6.0.29 and 5.0.34 fix MongoBleed and the two 2026 CVEs that name them, so a server on an older 6.0 or 5.0 patch release should move to those first. They do not have fixes for the 2025 and 2026 CVEs that list only 7.0 and later, such as the unauthenticated crashes CVE-2026-9740 and CVE-2026-25611, because MongoDB did not assess these lines for them. 5.0 and later need AVX on x86_64. See MongoDB 6.0 end of life and MongoDB 5.0 end of life.

MongoDB 4.4

4.4 is the last line that runs on x86_64 CPUs without AVX, which is why so many deployments stay on it. 4.4.30 and 4.4.31 fixed CVE-2025-14847 and CVE-2026-11933, but 4.4 is not listed for CVE-2026-8053, CVE-2025-3085, CVE-2024-10921 or anything after June 2026. See MongoDB 4.4 end of life and MongoDB's AVX requirement.

MongoDB 4.2 and older

4.2.25 from October 2023 is the last 4.2 release, and MongoDB shipped no fix for CVE-2025-14847 on 4.2, 4.0 or 3.6, although CISA lists it as exploited. Disabling zlib compression is the only upstream mitigation on these lines.

What to do on each line

  • 7.0, 8.0 and 8.3. Stay on the latest patch release.
  • 8.2. Move to 8.3.11.
  • 6.0 and 5.0. Move to 6.0.29 or 5.0.34 now, then plan the upgrade to 7.0 or 8.0, one major version at a time, or take patched builds.
  • 4.4 and older. Move 4.4 to 4.4.31. On every line, start mongod and mongos with networkMessageCompressors or net.compression.compressors set to snappy,zstd or disabled to remove zlib, require a CA file whenever TLS is on, keep server ports off untrusted networks, and turn off server-side JavaScript with security.javascriptEnabled: false if your applications do not use it.

For the upgrade path itself, see upgrading MongoDB 4.4, 5.0 or 6.0 to 7.0 or 8.0.

Where OSSeva fits

OSSeva ships patched builds of self-managed MongoDB 4.2, 4.4, 5.0 and 6.0, including 4.2 and 4.4 builds for hardware without AVX. OSSeva backports fixes of this class to the end-of-life release lines it patches, covering mongod, mongos and the bundled tools, and delivers them as signed packages and container images with SBOMs. They are available now on the Patch, Assure and Operate tiers. Assure adds an authentication, TLS and network exposure review, a featureCompatibilityVersion upgrade plan and a driver compatibility audit, and Operate adds 24/7 replica set and cluster monitoring with a 15-minute P1 response and a named MongoDB engineer. See MongoDB extended support.

Tags

MongoDBCVEMongoDB 4.4MongoDB 6.0End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.