MongoDB 8.x — End of Life
EOL soon Actively exploitedMongoDB 8.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 8.3 | May 31, 2026 | — | Oct 31, 2029 | 8.3.4 | Active | |
| 8.2 | Sep 30, 2025 | — | Jul 31, 2026 | 8.2.11 | EOL soon | |
| 8.1 | Jun 30, 2025 | — | Sep 30, 2025 | 8.1.3 | EOL | |
| 8.0 | Oct 31, 2024 | — | Oct 31, 2029 | 8.0.26 | Active |
CVEs affecting MongoDB 8.x (84)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9754 | MEDIUM | 6.5 | 0.22% | — | 8.3 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Jun 9, 2026 |
| CVE-2026-9754 | MEDIUM | 6.5 | 0.22% | — | 8.2 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 8.2 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 8.3 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9753 | HIGH | 8.1 | 0.30% | — | 8.0 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed … | Jun 9, 2026 |
| CVE-2026-9752 | MEDIUM | 6.5 | 0.27% | — | 8.0 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO… | Jun 9, 2026 |
| CVE-2026-9752 | MEDIUM | 6.5 | 0.27% | — | 8.2 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO… | Jun 9, 2026 |
| CVE-2026-9752 | MEDIUM | 6.5 | 0.27% | — | 8.3 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO… | Jun 9, 2026 |
| CVE-2026-9751 | MEDIUM | 5.5 | 0.11% | — | 8.2 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon… | Jun 9, 2026 |
| CVE-2026-9751 | MEDIUM | 5.5 | 0.11% | — | 8.0 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon… | Jun 9, 2026 |
| CVE-2026-9751 | MEDIUM | 5.5 | 0.11% | — | 8.3 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon… | Jun 9, 2026 |
| CVE-2026-9750 | MEDIUM | 6.5 | 0.37% | — | 8.3 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe… | Jun 9, 2026 |
| CVE-2026-9750 | MEDIUM | 6.5 | 0.37% | — | 8.0 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe… | Jun 9, 2026 |
| CVE-2026-9750 | MEDIUM | 6.5 | 0.37% | — | 8.2 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe… | Jun 9, 2026 |
| CVE-2026-9749 | MEDIUM | 6.5 | 0.27% | — | 8.2 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran… | Jun 9, 2026 |
| CVE-2026-9749 | MEDIUM | 6.5 | 0.27% | — | 8.3 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran… | Jun 9, 2026 |
| CVE-2026-9749 | MEDIUM | 6.5 | 0.27% | — | 8.0 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran… | Jun 9, 2026 |
| CVE-2026-9748 | MEDIUM | 6.5 | 0.32% | — | 8.2 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st… | Jun 9, 2026 |
| CVE-2026-9748 | MEDIUM | 6.5 | 0.32% | — | 8.0 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st… | Jun 9, 2026 |
| CVE-2026-9748 | MEDIUM | 6.5 | 0.32% | — | 8.3 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st… | Jun 9, 2026 |
| CVE-2026-9747 | MEDIUM | 6.5 | 0.27% | — | 8.0 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Jun 9, 2026 |
| CVE-2026-9747 | MEDIUM | 6.5 | 0.27% | — | 8.2 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Jun 9, 2026 |
| CVE-2026-9747 | MEDIUM | 6.5 | 0.27% | — | 8.3 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. | Jun 9, 2026 |
| CVE-2026-9746 | MEDIUM | 6.5 | 0.27% | — | 8.3 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which… | Jun 9, 2026 |
| CVE-2026-9746 | MEDIUM | 6.5 | 0.27% | — | 8.2 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which… | Jun 9, 2026 |
| CVE-2026-9746 | MEDIUM | 6.5 | 0.27% | — | 8.0 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which… | Jun 9, 2026 |
| CVE-2026-9743 | MEDIUM | 6.5 | 0.31% | — | 8.0 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines… | Jun 9, 2026 |
| CVE-2026-9742 | HIGH | 7.5 | 0.35% | — | 8.3 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th… | Jun 9, 2026 |
| CVE-2026-9742 | HIGH | 7.5 | 0.35% | — | 8.2 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th… | Jun 9, 2026 |
| CVE-2026-9741 | MEDIUM | 6.5 | 0.10% | — | 8.3 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F… | Jun 9, 2026 |
| CVE-2026-9741 | MEDIUM | 6.5 | 0.10% | — | 8.0 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F… | Jun 9, 2026 |
| CVE-2026-9741 | MEDIUM | 6.5 | 0.10% | — | 8.2 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F… | Jun 9, 2026 |
| CVE-2026-9740 | HIGH | 7.5 | 0.34% | — | 8.2 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by … | Jun 9, 2026 |
| CVE-2026-9740 | HIGH | 7.5 | 0.34% | — | 8.3 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by … | Jun 9, 2026 |
| CVE-2026-9740 | HIGH | 7.5 | 0.34% | — | 8.0 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by … | Jun 9, 2026 |
| CVE-2026-9735 | MEDIUM | 5.5 | 0.12% | — | 8.3 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W… | Jun 9, 2026 |
| CVE-2026-8336 | HIGH | 7.5 | 0.26% | — | 8.2 | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in… | May 13, 2026 |
| CVE-2026-8336 | HIGH | 7.5 | 0.26% | — | 8.3 | After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in… | May 13, 2026 |
| CVE-2026-8202 | MEDIUM | 4.3 | 0.26% | — | 8.2 | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r… | May 13, 2026 |
| CVE-2026-8202 | MEDIUM | 4.3 | 0.26% | — | 8.0 | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r… | May 13, 2026 |
| CVE-2026-8202 | MEDIUM | 4.3 | 0.26% | — | 8.3 | Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r… | May 13, 2026 |
| CVE-2026-8201 | MEDIUM | 6.4 | 0.13% | — | 8.3 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie… | May 13, 2026 |
| CVE-2026-8201 | MEDIUM | 6.4 | 0.13% | — | 8.2 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie… | May 13, 2026 |
| CVE-2026-8201 | MEDIUM | 6.4 | 0.13% | — | 8.0 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie… | May 13, 2026 |
| CVE-2026-8200 | LOW | 2.7 | 0.20% | — | 8.3 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc… | May 13, 2026 |
| CVE-2026-8200 | LOW | 2.7 | 0.20% | — | 8.2 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc… | May 13, 2026 |
| CVE-2026-8200 | LOW | 2.7 | 0.20% | — | 8.0 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc… | May 13, 2026 |
| CVE-2026-8199 | MEDIUM | 6.5 | 0.26% | — | 8.2 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny… | May 13, 2026 |
| CVE-2026-8199 | MEDIUM | 6.5 | 0.26% | — | 8.0 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny… | May 13, 2026 |
| CVE-2026-8199 | MEDIUM | 6.5 | 0.26% | — | 8.3 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny… | May 13, 2026 |
| CVE-2026-8053 | HIGH | 8.8 | 0.57% | — | 8.0 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv… | May 13, 2026 |
| CVE-2026-8053 | HIGH | 8.8 | 0.57% | — | 8.3 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv… | May 13, 2026 |
| CVE-2026-8053 | HIGH | 8.8 | 0.57% | — | 8.2 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv… | May 13, 2026 |
| CVE-2026-8063 | MEDIUM | 6.5 | 0.23% | — | 8.2 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When … | May 7, 2026 |
| CVE-2026-6915 | MEDIUM | 6.3 | 0.17% | — | 8.2 | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen… | Apr 29, 2026 |
| CVE-2026-6915 | MEDIUM | 6.3 | 0.17% | — | 8.0 | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen… | Apr 29, 2026 |
| CVE-2026-6914 | MEDIUM | 6.5 | 0.26% | — | 8.1 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD… | Apr 29, 2026 |
| CVE-2026-6914 | MEDIUM | 6.5 | 0.26% | — | 8.0 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD… | Apr 29, 2026 |
| CVE-2026-6914 | MEDIUM | 6.5 | 0.26% | — | 8.2 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD… | Apr 29, 2026 |
| CVE-2026-5170 | MEDIUM | 5.3 | 0.20% | — | 8.2 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during… | Mar 30, 2026 |
| CVE-2026-5170 | MEDIUM | 5.3 | 0.20% | — | 8.0 | A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during… | Mar 30, 2026 |
| CVE-2026-4358 | MEDIUM | 6.4 | 0.34% | — | 8.0 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre… | Mar 17, 2026 |
| CVE-2026-4358 | MEDIUM | 6.4 | 0.34% | — | 8.2 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre… | Mar 17, 2026 |
| CVE-2026-4148 | HIGH | 8.8 | 0.32% | — | 8.3 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu… | Mar 17, 2026 |
| CVE-2026-4148 | HIGH | 8.8 | 0.32% | — | 8.0 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu… | Mar 17, 2026 |
| CVE-2026-4148 | HIGH | 8.8 | 0.32% | — | 8.2 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu… | Mar 17, 2026 |
| CVE-2026-4147 | MEDIUM | 6.5 | 0.21% | — | 8.3 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Mar 17, 2026 |
| CVE-2026-4147 | MEDIUM | 6.5 | 0.21% | — | 8.0 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Mar 17, 2026 |
| CVE-2026-4147 | MEDIUM | 6.5 | 0.21% | — | 8.2 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is… | Mar 17, 2026 |
| CVE-2026-25613 | MEDIUM | 6.5 | 0.24% | — | 8.0 | An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo… | Feb 10, 2026 |
| CVE-2026-25613 | MEDIUM | 6.5 | 0.24% | — | 8.2 | An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo… | Feb 10, 2026 |
| CVE-2026-25610 | MEDIUM | 6.5 | 0.24% | — | 8.0 | An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints. | Feb 10, 2026 |
| CVE-2026-25609 | MEDIUM | 5.4 | 0.17% | — | 8.0 | Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read… | Feb 10, 2026 |
| CVE-2026-25609 | MEDIUM | 5.4 | 0.17% | — | 8.2 | Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read… | Feb 10, 2026 |
| CVE-2026-1850 | MEDIUM | 6.5 | 0.24% | — | 8.0 | Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. | Feb 10, 2026 |
| CVE-2026-1850 | MEDIUM | 6.5 | 0.24% | — | 8.2 | Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. | Feb 10, 2026 |
| CVE-2026-1849 | MEDIUM | 6.5 | 0.27% | — | 8.2 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents… | Feb 10, 2026 |
| CVE-2026-1849 | MEDIUM | 6.5 | 0.27% | — | 8.0 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents… | Feb 10, 2026 |
| CVE-2026-1848 | HIGH | 7.5 | 0.26% | — | 8.2 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i… | Feb 10, 2026 |
| CVE-2026-1848 | HIGH | 7.5 | 0.26% | — | 8.0 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i… | Feb 10, 2026 |
| CVE-2026-1847 | MEDIUM | 6.5 | 0.24% | — | 8.0 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o… | Feb 10, 2026 |
| CVE-2026-1847 | MEDIUM | 6.5 | 0.24% | — | 8.2 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o… | Feb 10, 2026 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 8.2 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
| CVE-2025-14847 | HIGH | 7.5 | 83.01% | KEV | 8.0 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe… | Dec 19, 2025 |
Frequently asked questions
Is MongoDB 8 end of life?
Partially. Some MongoDB 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect MongoDB 8?
There are 84 CVEs tracked for MongoDB 8.x and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest MongoDB 8 version?
The latest MongoDB 8.x patch release is 8.3.4, released on June 15, 2026. Always run the latest patch to benefit from all security fixes.
When was MongoDB 8 first released?
MongoDB 8.0 was initially released on May 31, 2026. See the full version timeline in the table above.
Is it safe to run MongoDB 8 in production?
MongoDB 8 is still supported and safe for production use until October 31, 2029. Ensure you are running the latest patch version (8.3.4) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
