MongoDB 5.x — End of Life
EOL Actively exploitedMongoDB 5.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 5.3 | Mar 31, 2022 | — | Jul 19, 2022 | 5.3.2 | EOL | |
| 5.2 | Jan 31, 2022 | — | Mar 23, 2022 | 5.2.1 | EOL | |
| 5.1 | Nov 30, 2021 | — | Jan 19, 2022 | 5.1.1 | EOL | |
| 5.0 | Jul 31, 2021 | — | Oct 31, 2024 | 5.0.34 | EOL |
CVEs affecting MongoDB 5.x (6)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 5.1 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 5.2 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 5.0 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 5.3 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-8053 | HIGH | 8.8 | 0.57% | — | 5.0 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv… | May 13, 2026 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 5.0 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
MongoDB 5.x is EOL — migrate to MongoDB 6.x
MongoDB 6.x is the next major release. Plan your upgrade before MongoDB 5.x stops receiving security patches.
Frequently asked questions
Is MongoDB 5 end of life?
Yes. All MongoDB 5.x releases have reached end of life and no longer receive security patches. There are 6 known CVEs affecting MongoDB 5.x. Migrate to MongoDB 6.x as soon as possible.
What CVEs affect MongoDB 5?
There are 6 CVEs tracked for MongoDB 5.x and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest MongoDB 5 version?
The latest MongoDB 5.x patch release is 5.3.2, released on June 15, 2022. Always run the latest patch to benefit from all security fixes.
How to migrate from MongoDB 5 to MongoDB 6?
To migrate from MongoDB 5 to MongoDB 6: (1) review the official MongoDB 6 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run MongoDB 5 in production?
No. MongoDB 5 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting MongoDB 5.x is in the CISA KEV catalog — meaning they are actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
