mongodb/mongodb
The Official MongoDB PHP library
Activity
- Latest release
- 4d ago
- Total releases
- 70
- Cadence
- ~44 days
- Last 12 months
- 8
Reach
- Stars
- 1.6k
Details
- License
- Apache-2.0
- First release
- Dec 12, 2014
| Version | Released | |
|---|---|---|
2.4.2
patch
| ||
1.21.5
patch
| ||
1.21.4
patch
| ||
2.4.1
patch
| ||
2.4.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.21.3
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.21.2
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.21.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.21.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.20.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.19.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.19.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.18.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.17.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.16.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.13.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.13.0-beta1
pre
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.10.1
patch
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.10.0
minor
1 CVE
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
1.9.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.9.0-alpha1
pre
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.8.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.8.0-RC1
pre
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.2
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.1
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.0-rc1
pre
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.0-beta2
pre
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.7.0-beta1
pre
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.6.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.5.2
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.5.1
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.5.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.4.3
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.4.2
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.4.1
patch
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2026-81525
GHSA-65fr-j4p9-vc33
Sep 08, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
Network
Low
Low
None
ImpactPassing untrusted input as part of a database or collection name may result in targeting a different database or collection than specified. PatchesFixed in PHP library 1.21.4 and 2.4.1. WorkaroundsValidate database and collection names prior to passing into APIs. Affected versions
0.1.0
0.2.0
1.0.0
1.0.0-alpha1
1.0.0-beta1
1.0.0-beta2
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
+ 54 more Show less
1.1.0-alpha1
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.13.0-beta1
1.13.1
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.2.0
1.2.0-alpha1
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.3.0
2.4.0
Fixed in
1.21.4
2.4.1
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2021-32050
GHSA-vxvm-qww3-2fh7
Aug 29, 2023
MongoDB Driver may publish events containing authentication-related data
4.2
/ 10
Medium
Local
Low
High
Required
Unchanged
High
None
None
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0). Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.0-alpha1
1.1.1
1.1.2
1.2.0
1.2.0-alpha1
+ 22 more Show less
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.0-beta1
1.7.0-beta2
1.7.0-rc1
1.7.1
1.7.2
1.8.0
1.8.0-RC1
1.9.0
1.9.0-alpha1
Fixed in
1.9.2
References
Updated Nov 03, 2025 · Source: OSV.dev |