FAIL › dossier
MongoDB
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 50%
MongoDB is a leading document-oriented database with a public profile but a concerning security track record marked by recent high-severity RCE flaws. Its ecosystem shows recurring vulnerabilities in memory handling and third-party components, requiring strict patching and validation protocols for defense-industrial-base environments.
PROFILE
CategoryDatabase SoftwareWhat they doMongoDB is a cross-platform, document-oriented database program that provides high performance and high availability.
SECURITY POSTURE
MongoDB has a mixed security track record, with recent high-severity RCE vulnerabilities indicating potential gaps in memory safety and input validation across its ecosystem.
Notable failures
- CVE-2025-14847: Uninitialized heap memory exposure via Zlib headers
- CVE-2019-10758: RCE in mongo-express via toBSON method
Patterns: Remote Code Execution vulnerabilities; Memory safety issues in third-party integrations
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-12-10 | CVE-2019-10758 | high | MongoDB mongo-express versions before 0.54.0 suffered a remote code execution flaw via the toBSON method. |
| 2025-12-29 | CVE-2025-14847 | high | MongoDB exposed uninitialized heap memory through Zlib protocol headers |
FEDRAMP CATALOG PRODUCTS · 1
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| MongoDB Atlas for Government | Authorized | Moderate |
Open questions: MongoDB's current patching SLA for RCE vulnerabilities · Whether MongoDB has implemented memory-safe alternatives to Zlib in recent versions
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 04:01:58.060002+00:00