MongoDB 8.0 lifecycle
Current status
MongoDB 8.0 is currently in standard support.
Official lifecycle source: MongoDB Server lifecycle schedule
- Support phase
- standard support
- End of life
- 31 Oct 2029
- Latest release
- 8.0.29
- Released
- 11 Aug 2026
At a glance
- Version line
- 8.0
- Initial release
- 2 Oct 2024
- Lifecycle phase
- standard support
- Latest stable
- 8.0.29
- Latest release date
- 11 Aug 2026
- EOL
- 31 Oct 2029
- Until EOL
- ~38 months
- Risk
- low
- Releases tracked
- 27
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
2 Oct 2024
standard supportcurrent
2 Oct 2024 → 31 Oct 2029
Source: MongoDB Server lifecycle schedule
end of life
31 Oct 2029 → —
Source: MongoDB Server lifecycle schedule
MongoDB 8.0 is currently in standard support.
Security
Advisories affecting MongoDB 8.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-13073
MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination
- Affected:
- >=8.0.0,<8.0.28
- Fixed in:
- 8.0.28
- Source:
- OSV source · Advisory
- CVE-2026-9743
Aggregation sub-pipeline null dereference may allow DoS via crafted getMore
- Affected:
- >=8.0.0,<8.0.24
- Fixed in:
- 8.0.24
- Source:
- OSV source · Advisory
- CVE-2026-25610
Invalid $geoNear index hint may cause server crash
- Affected:
- >=8.0.0,<8.0.13
- Fixed in:
- 8.0.13
- Source:
- OSV source · Advisory
- CVE-2025-12657
Malformed KMIP response may result in access violation
- Affected:
- >=8.0.0,<8.0.10
- Fixed in:
- 8.0.10
- Source:
- OSV source · Advisory
- CVE-2025-11979
Use-after-free in the MongoDB server query planner may lead to crash or undefined behavior
- Affected:
- >=8.0.0,<8.0.15
- Fixed in:
- 8.0.15
- Source:
- OSV source · Advisory
- CVE-2025-10060
MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation
- Affected:
- >=8.0.0,<8.0.12
- Fixed in:
- 8.0.12
- Source:
- OSV source · Advisory
- CVE-2025-10059
MongoDB Server router will crash when incorrect lsid is set on a sharded query
- Affected:
- >=8.0.0,<8.0.6
- Fixed in:
- 8.0.6
- Source:
- OSV source · Advisory
- CVE-2025-6714
Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections
- Affected:
- >=8.0.0,<8.0.9
- Fixed in:
- 8.0.9
- Source:
- OSV source · Advisory
- CVE-2025-6713
MongoDB Server may be susceptible to privilege escalation due to $mergeCursors stage
- Affected:
- >=8.0.0,<8.0.7
- Fixed in:
- 8.0.7
- Source:
- OSV source · Advisory
- CVE-2025-6712
MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation
- Affected:
- >=8.0.0,<8.0.10
- Fixed in:
- 8.0.10
- Source:
- OSV source · Advisory
- CVE-2025-6711
Incomplete Redaction of Sensitive Information in MongoDB Server Logs
- Affected:
- >=8.0.0,<8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source · Advisory
- CVE-2025-6710
Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB
- Affected:
- >=8.0.0,<8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source · Advisory
- CVE-2025-6709
Pre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC Authentication
- Affected:
- >=8.0.0,<8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source · Advisory
- CVE-2025-6707
Race condition in privilege cache invalidation cycle
- Affected:
- >=8.0.0,<8.0.5
- Fixed in:
- 8.0.5
- Source:
- OSV source · Advisory
- CVE-2025-6706
Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server
- Affected:
- >=8.0.0,<8.0.4
- Fixed in:
- 8.0.4
- Source:
- OSV source · Advisory
Latest release
Previous releases
8.0.28
22 Jul 2026
8.0.26
11 Jun 2026
8.0.25
10 Jun 2026
Release history
27 concrete releases tracked for this line.
| Version | Release date | Channel | Source |
|---|---|---|---|
| 8.0.29 | 11 Aug 2026 | stable | Source |
| 8.0.28 | 22 Jul 2026 | stable | Source |
| 8.0.26 | 11 Jun 2026 | stable | Source |
| 8.0.25 | 10 Jun 2026 | stable | Source |
| 8.0.24 | 9 Jun 2026 | stable | Source |
| 8.0.23 | 12 May 2026 | stable | Source |
| 8.0.21 | 29 Apr 2026 | stable | Source |
| 8.0.20 | 17 Mar 2026 | stable | Source |
| 8.0.19 | 10 Feb 2026 | stable | Source |
| 8.0.18 | 27 Jan 2026 | stable | Source |
| 8.0.17 | 19 Dec 2025 | stable | Source |
| 8.0.16 | 19 Nov 2025 | stable | Source |
| 8.0.15 | 2 Oct 2025 | stable | Source |
| 8.0.14 | 25 Sept 2025 | stable | Source |
| 8.0.13 | 21 Aug 2025 | stable | Source |
| 8.0.12 | 23 Jul 2025 | stable | Source |
| 8.0.11 | 30 Jun 2025 | stable | Source |
| 8.0.10 | 4 Jun 2025 | stable | Source |
| 8.0.9 | 1 May 2025 | stable | Source |
| 8.0.8 | 14 Apr 2025 | stable | Source |
| 8.0.7 | 14 Apr 2025 | stable | Source |
| 8.0.6 | 19 Mar 2025 | stable | Source |
| 8.0.5 | 20 Feb 2025 | stable | Source |
| 8.0.4 | 9 Dec 2024 | stable | Source |
| 8.0.3 | 24 Oct 2024 | stable | Source |
Release activity
- Total releases
- 27
- Last 30 days
- 1
- Last 90 days
- 5
- Avg. interval
- ~27 days
- Most recent
- 11 Aug 2026
Should I use this version?
Suitable for new deployments
MongoDB 8.0 is currently supported (standard support).
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- MongoDB Server lifecycle schedulefirst party · high confidence
Official source: https://www.mongodb.com/legal/support-policy/lifecycles
Last verified 1 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- MongoDB Server lifecycle schedulefirst party · high confidence
Official source: https://www.mongodb.com/legal/support-policy/lifecycles
Last verified 1 Sept 2026
- MongoDB Server release notesfirst party
Official source: https://www.mongodb.com/docs/manual/release-notes/
Verification time not recorded
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 27
- Lifecycle periods
- 2
- EOL
- Known
- Provenance records
- 3
- Data last checked
- 1 Sept 2026
- Latest source update
- 1 Sept 2026
