mongodb
The official MongoDB Rust Driver
Activity
- Latest release
- 3d ago
- Total releases
- 103
- Cadence
- ~30 days
- Last 12 months
- 11
Reach
- Downloads
- 17.1M
- Stars
- 1.5k
Details
- License
- Apache-2.0
- First release
- May 22, 2015
| Version | Released | |
|---|---|---|
3.9.1
patch
|
3.9.1
patch
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.9.0
minor
|
3.9.0
minor
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.8.2
patch
|
3.8.2
patch
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.8.1
patch
|
3.8.1
patch
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.8.0
unknown
|
3.8.0
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.7.0
unknown
|
3.7.0
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.6.0
unknown
|
3.6.0
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.5.2
unknown
|
3.5.2
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.5.1
unknown
|
3.5.1
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.5.0
unknown
|
3.5.0
unknown
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.4.1
unknown
|
3.4.1
unknown
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
3.3.0
unknown
|
3.3.0
unknown
Dependencies (84)
+ 76 more
Changelog
Compare changes
|
|
3.2.5
unknown
|
3.2.5
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.2.4
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.2.4
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.2.3
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.2.3
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.2.2
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.2.2
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.2.1
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.2.1
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.2.0
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.2.0
unknown
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.1.1
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.1.1
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
3.1.0
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.1.0
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
3.0.1
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.0.1
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
3.0.0
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.0.0
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
3.0.0-beta
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
3.0.0-beta
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
2.8.2
unknown
1 CVE
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev |
2.8.2
unknown
Dependencies (72)
+ 64 more
Changelog
Compare changes
|
|
2.8.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.8.1
unknown
Dependencies (72)
+ 64 more
Changelog
Compare changes
|
|
2.8.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.8.0
unknown
Dependencies (72)
+ 64 more
Changelog
Compare changes
|
|
2.7.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.7.1
unknown
Dependencies (73)
+ 65 more
Changelog
Compare changes
|
|
2.7.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.7.0
unknown
Dependencies (73)
+ 65 more
Changelog
Compare changes
|
|
2.7.0-beta.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.7.0-beta.1
unknown
Dependencies (72)
+ 64 more
Changelog
Compare changes
|
|
2.7.0-beta
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.7.0-beta
unknown
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
2.6.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.6.1
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.6.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.6.0
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.5.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.5.0
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.4.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.4.0
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.4.0-beta.2
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.4.0-beta.2
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.4.0-beta.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.4.0-beta.1
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.4.0-beta
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.4.0-beta
unknown
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
2.3.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.3.1
unknown
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
2.3.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.3.0
unknown
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
2.3.0-beta
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.3.0-beta
unknown
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
2.2.2
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.2.2
unknown
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
2.2.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.2.1
unknown
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
2.2.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.2.0
unknown
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
2.2.0-beta
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.2.0-beta
unknown
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.2.5
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2021-20332
GHSA-4rjr-3gj2-5crq
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver
4.4
/ 10
Medium
Local
Low
High
None
Unchanged
High
None
None
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default. Fixed in
2.0.0-beta
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.5
unknown
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
2.1.0
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.1.0
unknown
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
2.1.0-beta
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.1.0-beta
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
1.2.4
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2021-20332
GHSA-4rjr-3gj2-5crq
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver
4.4
/ 10
Medium
Local
Low
High
None
Unchanged
High
None
None
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default. Fixed in
2.0.0-beta
References Updated Nov 08, 2023 · Source: OSV.dev |
1.2.4
unknown
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
2.0.2
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.0.2
unknown
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
2.0.1
unknown
2 CVEs
CVE-2025-11695
GHSA-3p6w-gv5g-xjw9
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8.0
/ 10
High
Network
High
None
Required
Changed
High
High
None
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5. Fixed in
3.2.5
References
Updated Oct 13, 2025 · Source: OSV.dev
CVE-2024-6382
GHSA-32jf-h775-g29h
Jul 02, 2024
MongoDB Rust driver may issue unintended commands
6.4
/ 10
Medium
Network
Low
Low
None
Changed
None
Low
Low
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2 Fixed in
2.8.2
References
Updated Oct 02, 2025 · Source: OSV.dev |
2.0.1
unknown
Dependencies (50)
+ 42 more
Changelog
Compare changes
|