MongoDB 7.x — End of Life
Active Actively exploitedMongoDB 7.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 7.3 | Mar 31, 2024 | — | Oct 2, 2024 | 7.3.4 | EOL | |
| 7.2 | Jan 31, 2024 | — | Mar 27, 2024 | 7.2.2 | EOL | |
| 7.1 | Oct 31, 2023 | — | Jan 23, 2024 | 7.1.1 | EOL | |
| 7.0 | Aug 31, 2023 | — | Aug 31, 2027 | 7.0.37 | Active |
CVEs affecting MongoDB 7.x (28)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 7.0 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9752 | MEDIUM | 6.5 | 0.27% | — | 7.0 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO… | Jun 9, 2026 |
| CVE-2026-9751 | MEDIUM | 5.5 | 0.11% | — | 7.0 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon… | Jun 9, 2026 |
| CVE-2026-9750 | MEDIUM | 6.5 | 0.37% | — | 7.0 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe… | Jun 9, 2026 |
| CVE-2026-9749 | MEDIUM | 6.5 | 0.27% | — | 7.0 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran… | Jun 9, 2026 |
| CVE-2026-9748 | MEDIUM | 6.5 | 0.32% | — | 7.0 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st… | Jun 9, 2026 |
| CVE-2026-9747 | MEDIUM | 6.5 | 0.27% | — | 7.0 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Jun 9, 2026 |
| CVE-2026-9746 | MEDIUM | 6.5 | 0.27% | — | 7.0 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which… | Jun 9, 2026 |
| CVE-2026-9741 | MEDIUM | 6.5 | 0.10% | — | 7.0 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F… | Jun 9, 2026 |
| CVE-2026-9740 | HIGH | 7.5 | 0.34% | — | 7.0 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by … | Jun 9, 2026 |
| CVE-2026-8202 | MEDIUM | 4.3 | 0.26% | — | 7.0 | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r… | May 13, 2026 |
| CVE-2026-8201 | MEDIUM | 6.4 | 0.13% | — | 7.0 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie… | May 13, 2026 |
| CVE-2026-8200 | LOW | 2.7 | 0.20% | — | 7.0 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc… | May 13, 2026 |
| CVE-2026-8199 | MEDIUM | 6.5 | 0.26% | — | 7.0 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny… | May 13, 2026 |
| CVE-2026-8053 | HIGH | 8.8 | 0.57% | — | 7.0 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv… | May 13, 2026 |
| CVE-2026-6915 | MEDIUM | 6.3 | 0.17% | — | 7.0 | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen… | Apr 29, 2026 |
| CVE-2026-6914 | MEDIUM | 6.5 | 0.26% | — | 7.0 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD… | Apr 29, 2026 |
| CVE-2026-5170 | MEDIUM | 5.3 | 0.20% | — | 7.0 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during… | Mar 30, 2026 |
| CVE-2026-4358 | MEDIUM | 6.4 | 0.34% | — | 7.0 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre… | Mar 17, 2026 |
| CVE-2026-4148 | HIGH | 8.8 | 0.32% | — | 7.0 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu… | Mar 17, 2026 |
| CVE-2026-4147 | MEDIUM | 6.5 | 0.21% | — | 7.0 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Mar 17, 2026 |
| CVE-2026-25613 | MEDIUM | 6.5 | 0.24% | — | 7.0 | An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo… | Feb 10, 2026 |
| CVE-2026-25610 | MEDIUM | 6.5 | 0.24% | — | 7.0 | An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints. | Feb 10, 2026 |
| CVE-2026-25609 | MEDIUM | 5.4 | 0.17% | — | 7.0 | Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read… | Feb 10, 2026 |
| CVE-2026-1849 | MEDIUM | 6.5 | 0.27% | — | 7.0 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents… | Feb 10, 2026 |
| CVE-2026-1848 | HIGH | 7.5 | 0.26% | — | 7.0 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i… | Feb 10, 2026 |
| CVE-2026-1847 | MEDIUM | 6.5 | 0.24% | — | 7.0 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o… | Feb 10, 2026 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 7.0 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
MongoDB 7.x will reach end of life — migrate to MongoDB 8.x
MongoDB 8.x is the next major release. Plan your upgrade before MongoDB 7.x stops receiving security patches.
Frequently asked questions
Is MongoDB 7 end of life?
Partially. Some MongoDB 7.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect MongoDB 7?
There are 28 CVEs tracked for MongoDB 7.x and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest MongoDB 7 version?
The latest MongoDB 7.x patch release is 7.3.4, released on August 14, 2024. Always run the latest patch to benefit from all security fixes.
How to migrate from MongoDB 7 to MongoDB 8?
To migrate from MongoDB 7 to MongoDB 8: (1) review the official MongoDB 8 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run MongoDB 7 in production?
MongoDB 7 is still supported and safe for production use until October 2, 2024. Ensure you are running the latest patch version (7.3.4) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
