mongodb
Safeguard articles tagged "mongodb" — guides, analysis, and best practices for software supply chain and application security.
5 articles
CVE-2019-10758: MongoDB mongo-express Remote Code Execution Vulnerability
CVE-2019-10758 affects MongoDB mongo-express and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-10.
CVE-2025-14847: MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
CVE-2025-14847 affects MongoDB MongoDB and MongoDB Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-29.
Four Lower-Profile CVEs Across a File Server, a Database, an NVR, and an Email Gateway
Wing FTP Server, MongoDB, a Digiever network video recorder, and Libraesva's email security gateway each produced a confirmed-exploited CVE, none scoring above 8.8.
NoSQL injection prevention in MongoDB and Mongoose
A single unsanitized query key like $ne can bypass authentication in MongoDB apps — two 2024-2025 Mongoose CVEs show the fix is harder than one middleware package.
MongoDB Atlas Breach: Customer Metadata Exposed in Corporate Systems Attack
MongoDB disclosed unauthorized access to its corporate systems in December 2023, exposing customer metadata and contact information while Atlas cluster data remained secure.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.