MongoDB 8.x — End of Life

EOL soon High risk
EOL: Oct 31, 2029in 1240d4 releases in this series18 CVEs

MongoDB 8.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
8.3May 4, 2026Oct 31, 20298.3.1Active
8.2Sep 17, 2025Jul 31, 20268.2.6EOL soon
8.1Jun 20, 2025Sep 30, 20258.1.3EOL
8.0Oct 31, 2024Oct 31, 20298.0.21Active

CVEs affecting MongoDB 8.x (18)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-8053HIGH8.80.09%8.2An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8053HIGH8.80.09%8.3An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8053HIGH8.80.09%8.0An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8336HIGH7.50.08%8.3After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in…May 13, 2026
CVE-2026-8336HIGH7.50.08%8.2After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in…May 13, 2026
CVE-2026-8063MEDIUM6.50.07%8.2An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When …May 7, 2026
CVE-2026-8199MEDIUM6.50.05%8.0An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8199MEDIUM6.50.05%8.2An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8199MEDIUM6.50.05%8.3An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8201MEDIUM6.40.03%8.0A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8201MEDIUM6.40.03%8.2A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8201MEDIUM6.40.03%8.3A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8202MEDIUM4.30.05%8.3Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8202MEDIUM4.30.05%8.0Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8202MEDIUM4.30.05%8.2Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8200LOW2.70.04%8.0When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026
CVE-2026-8200LOW2.70.04%8.2When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026
CVE-2026-8200LOW2.70.04%8.3When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026

Frequently asked questions

Is MongoDB 8 end of life?

Partially. Some MongoDB 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect MongoDB 8?

There are 18 CVEs tracked for MongoDB 8.x. See the full list above with CVSS and EPSS scores.

What is the latest MongoDB 8 version?

The latest MongoDB 8.x patch release is 8.3.1, released on May 4, 2026. Always run the latest patch to benefit from all security fixes.

When was MongoDB 8 first released?

MongoDB 8.0 was initially released on May 4, 2026. See the full version timeline in the table above.

Is it safe to run MongoDB 8 in production?

MongoDB 8 is still supported and safe for production use until October 31, 2029. Ensure you are running the latest patch version (8.3.1) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA