MongoDB 4.x — End of Life
EOL Actively exploitedMongoDB 4.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 4.4 | Jul 31, 2020 | — | Feb 29, 2024 | 4.4.31 | EOL | |
| 4.2 | Aug 31, 2019 | — | Apr 30, 2023 | 4.2.25 | EOL | |
| 4.0 | Jun 30, 2018 | — | Apr 30, 2022 | 4.0.28 | EOL |
CVEs affecting MongoDB 4.x (6)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 4.0 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 4.2 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 4.4 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 4.0 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 4.2 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 4.4 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
MongoDB 4.x is EOL — migrate to MongoDB 5.x
MongoDB 5.x is the next major release. Plan your upgrade before MongoDB 4.x stops receiving security patches.
Frequently asked questions
Is MongoDB 4 end of life?
Yes. All MongoDB 4.x releases have reached end of life and no longer receive security patches. There are 6 known CVEs affecting MongoDB 4.x. Migrate to MongoDB 5.x as soon as possible.
What CVEs affect MongoDB 4?
There are 6 CVEs tracked for MongoDB 4.x and 3 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest MongoDB 4 version?
The latest MongoDB 4.x patch release is 4.4.31, released on June 24, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from MongoDB 4 to MongoDB 5?
To migrate from MongoDB 4 to MongoDB 5: (1) review the official MongoDB 5 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run MongoDB 4 in production?
No. MongoDB 4 has reached end of life and security vulnerabilities are no longer patched. Critically, 3 CVEs affecting MongoDB 4.x are in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
