Skip to content
COOEY

FAIL › dossier

MongoDB

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 50%

MongoDB is a leading document-oriented database with a public profile but a concerning security track record marked by recent high-severity RCE flaws. Its ecosystem shows recurring vulnerabilities in memory handling and third-party components, requiring strict patching and validation protocols for defense-industrial-base environments.

PROFILE
CategoryDatabase SoftwareWhat they doMongoDB is a cross-platform, document-oriented database program that provides high performance and high availability.
SECURITY POSTURE

MongoDB has a mixed security track record, with recent high-severity RCE vulnerabilities indicating potential gaps in memory safety and input validation across its ecosystem.

Notable failures
  • CVE-2025-14847: Uninitialized heap memory exposure via Zlib headers
  • CVE-2019-10758: RCE in mongo-express via toBSON method
Patterns: Remote Code Execution vulnerabilities; Memory safety issues in third-party integrations
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2021-12-10 CVE-2019-10758 high MongoDB mongo-express versions before 0.54.0 suffered a remote code execution flaw via the toBSON method.
2025-12-29 CVE-2025-14847 high MongoDB exposed uninitialized heap memory through Zlib protocol headers
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
MongoDB Atlas for GovernmentAuthorizedModerate
Open questions: MongoDB's current patching SLA for RCE vulnerabilities · Whether MongoDB has implemented memory-safe alternatives to Zlib in recent versions
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 04:01:58.060002+00:00