CERT-FR Flags Multiple MongoDB Driver Vulnerabilities
CERT-FR advisory details multiple MongoDB vulnerabilities across drivers and server that can cause DoS, data integrity loss, and confidentiality breaches.
CERT-FR published an advisory (CERTFR-2026-AVI-1169) covering multiple vulnerabilities discovered in MongoDB, affecting a broad range of official drivers (C, C#, C++, Go, Java, PHP, Python, Ruby, Rust) and the Core Server itself. The flaws, tracked across 15 distinct CVEs, allow an attacker to cause remote denial of service, breach data confidentiality, and compromise data integrity. No indication of active exploitation in the wild is mentioned in the advisory.
Affected versions span nearly all MongoDB driver ecosystems and server releases prior to 7.0.43, 8.0.32, 8.3.11, and 9.1.0-rc0, along with driver-specific version thresholds (e.g., C Driver <1.30.10/<2.5.3, Python Driver <4.18.1, Java Driver <5.11.1, etc.). This wide scope indicates the vulnerabilities likely stem from shared underlying libraries or protocol handling logic used across the driver implementations.
Defenders running MongoDB deployments or applications using any of the listed driver versions should consult the referenced MongoDB Jira security bulletins and CVE records to identify exact impact per component, then upgrade to the fixed versions noted in the advisory. Given the number of affected components (drivers plus core server) and the mix of confidentiality, integrity, and availability impacts, prioritize patching of internet-facing or multi-tenant MongoDB instances first.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1169
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free