MongoDB 8.x — End of Life

EOL soon Actively exploited
EOL: Oct 31, 2029in 1194d4 releases in this series84 CVEs

MongoDB 8.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
8.3May 31, 2026Oct 31, 20298.3.4Active
8.2Sep 30, 2025Jul 31, 20268.2.11EOL soon
8.1Jun 30, 2025Sep 30, 20258.1.3EOL
8.0Oct 31, 2024Oct 31, 20298.0.26Active

CVEs affecting MongoDB 8.x (84)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-9754MEDIUM6.50.22%8.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Jun 9, 2026
CVE-2026-9754MEDIUM6.50.22%8.2An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Jun 9, 2026
CVE-2026-9753HIGH8.10.30%8.2The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9753HIGH8.10.30%8.3The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9753HIGH8.10.30%8.0The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed …Jun 9, 2026
CVE-2026-9752MEDIUM6.50.27%8.0An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO…Jun 9, 2026
CVE-2026-9752MEDIUM6.50.27%8.2An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO…Jun 9, 2026
CVE-2026-9752MEDIUM6.50.27%8.3An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO…Jun 9, 2026
CVE-2026-9751MEDIUM5.50.11%8.2The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon…Jun 9, 2026
CVE-2026-9751MEDIUM5.50.11%8.0The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon…Jun 9, 2026
CVE-2026-9751MEDIUM5.50.11%8.3The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon…Jun 9, 2026
CVE-2026-9750MEDIUM6.50.37%8.3An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe…Jun 9, 2026
CVE-2026-9750MEDIUM6.50.37%8.0An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe…Jun 9, 2026
CVE-2026-9750MEDIUM6.50.37%8.2An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe…Jun 9, 2026
CVE-2026-9749MEDIUM6.50.27%8.2This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran…Jun 9, 2026
CVE-2026-9749MEDIUM6.50.27%8.3This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran…Jun 9, 2026
CVE-2026-9749MEDIUM6.50.27%8.0This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran…Jun 9, 2026
CVE-2026-9748MEDIUM6.50.32%8.2The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st…Jun 9, 2026
CVE-2026-9748MEDIUM6.50.32%8.0The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st…Jun 9, 2026
CVE-2026-9748MEDIUM6.50.32%8.3The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st…Jun 9, 2026
CVE-2026-9747MEDIUM6.50.27%8.0Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.Jun 9, 2026
CVE-2026-9747MEDIUM6.50.27%8.2Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.Jun 9, 2026
CVE-2026-9747MEDIUM6.50.27%8.3Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.Jun 9, 2026
CVE-2026-9746MEDIUM6.50.27%8.3When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which…Jun 9, 2026
CVE-2026-9746MEDIUM6.50.27%8.2When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which…Jun 9, 2026
CVE-2026-9746MEDIUM6.50.27%8.0When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which…Jun 9, 2026
CVE-2026-9743MEDIUM6.50.31%8.0In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines…Jun 9, 2026
CVE-2026-9742HIGH7.50.35%8.3When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th…Jun 9, 2026
CVE-2026-9742HIGH7.50.35%8.2When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th…Jun 9, 2026
CVE-2026-9741MEDIUM6.50.10%8.3A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F…Jun 9, 2026
CVE-2026-9741MEDIUM6.50.10%8.0A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F…Jun 9, 2026
CVE-2026-9741MEDIUM6.50.10%8.2A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F…Jun 9, 2026
CVE-2026-9740HIGH7.50.34%8.2A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by …Jun 9, 2026
CVE-2026-9740HIGH7.50.34%8.3A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by …Jun 9, 2026
CVE-2026-9740HIGH7.50.34%8.0A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by …Jun 9, 2026
CVE-2026-9735MEDIUM5.50.12%8.3MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W…Jun 9, 2026
CVE-2026-8336HIGH7.50.26%8.2After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in…May 13, 2026
CVE-2026-8336HIGH7.50.26%8.3After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in…May 13, 2026
CVE-2026-8202MEDIUM4.30.26%8.2Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8202MEDIUM4.30.26%8.0Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8202MEDIUM4.30.26%8.3Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r…May 13, 2026
CVE-2026-8201MEDIUM6.40.13%8.3A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8201MEDIUM6.40.13%8.2A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8201MEDIUM6.40.13%8.0A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie…May 13, 2026
CVE-2026-8200LOW2.70.20%8.3When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026
CVE-2026-8200LOW2.70.20%8.2When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026
CVE-2026-8200LOW2.70.20%8.0When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc…May 13, 2026
CVE-2026-8199MEDIUM6.50.26%8.2An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8199MEDIUM6.50.26%8.0An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8199MEDIUM6.50.26%8.3An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny…May 13, 2026
CVE-2026-8053HIGH8.80.57%8.0An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8053HIGH8.80.57%8.3An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8053HIGH8.80.57%8.2An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv…May 13, 2026
CVE-2026-8063MEDIUM6.50.23%8.2An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When …May 7, 2026
CVE-2026-6915MEDIUM6.30.17%8.2An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen…Apr 29, 2026
CVE-2026-6915MEDIUM6.30.17%8.0An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen…Apr 29, 2026
CVE-2026-6914MEDIUM6.50.26%8.1Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD…Apr 29, 2026
CVE-2026-6914MEDIUM6.50.26%8.0Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD…Apr 29, 2026
CVE-2026-6914MEDIUM6.50.26%8.2Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD…Apr 29, 2026
CVE-2026-5170MEDIUM5.30.20%8.2A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during…Mar 30, 2026
CVE-2026-5170MEDIUM5.30.20%8.0A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during…Mar 30, 2026
CVE-2026-4358MEDIUM6.40.34%8.0A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre…Mar 17, 2026
CVE-2026-4358MEDIUM6.40.34%8.2A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre…Mar 17, 2026
CVE-2026-4148HIGH8.80.32%8.3A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu…Mar 17, 2026
CVE-2026-4148HIGH8.80.32%8.0A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu…Mar 17, 2026
CVE-2026-4148HIGH8.80.32%8.2A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu…Mar 17, 2026
CVE-2026-4147MEDIUM6.50.21%8.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Mar 17, 2026
CVE-2026-4147MEDIUM6.50.21%8.0An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Mar 17, 2026
CVE-2026-4147MEDIUM6.50.21%8.2An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is…Mar 17, 2026
CVE-2026-25613MEDIUM6.50.24%8.0An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo…Feb 10, 2026
CVE-2026-25613MEDIUM6.50.24%8.2An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo…Feb 10, 2026
CVE-2026-25610MEDIUM6.50.24%8.0An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.Feb 10, 2026
CVE-2026-25609MEDIUM5.40.17%8.0Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read…Feb 10, 2026
CVE-2026-25609MEDIUM5.40.17%8.2Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read…Feb 10, 2026
CVE-2026-1850MEDIUM6.50.24%8.0Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.Feb 10, 2026
CVE-2026-1850MEDIUM6.50.24%8.2Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.Feb 10, 2026
CVE-2026-1849MEDIUM6.50.27%8.2MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents…Feb 10, 2026
CVE-2026-1849MEDIUM6.50.27%8.0MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents…Feb 10, 2026
CVE-2026-1848HIGH7.50.26%8.2Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i…Feb 10, 2026
CVE-2026-1848HIGH7.50.26%8.0Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i…Feb 10, 2026
CVE-2026-1847MEDIUM6.50.24%8.0Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o…Feb 10, 2026
CVE-2026-1847MEDIUM6.50.24%8.2Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o…Feb 10, 2026
CVE-2025-14847HIGH7.583.01% KEV 8.2Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe…Dec 19, 2025
CVE-2025-14847HIGH7.583.01% KEV 8.0Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe…Dec 19, 2025

Frequently asked questions

Is MongoDB 8 end of life?

Partially. Some MongoDB 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect MongoDB 8?

There are 84 CVEs tracked for MongoDB 8.x and 2 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest MongoDB 8 version?

The latest MongoDB 8.x patch release is 8.3.4, released on June 15, 2026. Always run the latest patch to benefit from all security fixes.

When was MongoDB 8 first released?

MongoDB 8.0 was initially released on May 31, 2026. See the full version timeline in the table above.

Is it safe to run MongoDB 8 in production?

MongoDB 8 is still supported and safe for production use until October 31, 2029. Ensure you are running the latest patch version (8.3.4) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA