« Back to list

Mongodb

Mongodb Java Driver: vulnerabilities and CVEs

Mongodb Java Driver has 4 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-88033Medium (6.1)0.46%—Sep 10, 2026
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather…
CVE-2026-88032High (8.2)0.26%—Sep 10, 2026
A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is…
CVE-2026-18710High (8.2)0.14%—Aug 11, 2026
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization.…
CVE-2021-20328Medium (6.8)0.44%—Feb 25, 2021
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a…

Other products by Mongodb