MongoDB 8.2 lifecycle

Current status

end of lifehigh

MongoDB 8.2 reached end of life on 31 Jul 2026. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Official lifecycle source: MongoDB Server lifecycle schedule

Support phase
end of life
End of life
31 Jul 2026
Latest release
Released

At a glance

Version line
8.2
Initial release
1 Sept 2025
Lifecycle phase
end of life
Latest stable
Latest release date
EOL
31 Jul 2026
Risk
high
Releases tracked
0

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    1 Sept 2025

  2. standard support

    1 Sept 2025 → 31 Jul 2026

    Source: MongoDB Server lifecycle schedule

  3. end of lifecurrent

    31 Jul 2026 → —

    Source: MongoDB Server lifecycle schedule

MongoDB 8.2 reached end of life on 31 Jul 2026. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Security

Advisories affecting MongoDB 8.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
1
Highest CVSS
7.5
  • CVE-2025-14847Known exploited

    MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

    Zlib compressed protocol header length confusion may allow memory read

    CISA KEV:
    listed · added 2025-12-29 · due 2026-01-19
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-130
    Affected:
    >=8.2.0,<8.2.3
    Fixed in:
    8.2.3
    Source:
    CISA KEV · Advisory
  • CVE-2026-8063

    Post-auth null pointer dereference when aggregating against a view with empty search pipeline

    Affected:
    >=8.2.0,<8.2.7
    Fixed in:
    8.2.7
    Source:
    OSV source · Advisory
  • CVE-2026-6915

    Flaw in the updateUser Command May Allow Unauthorized Configuration Change

    Affected:
    >=8.2.0,<8.2.7
    Fixed in:
    8.2.7
    Source:
    OSV source · Advisory
  • CVE-2026-6914

    MD5 checksum creation may cause availability loss

    Affected:
    >=8.1.0,<8.2.7
    Fixed in:
    8.2.7
    Source:
    OSV source · Advisory
  • CVE-2026-5170

    Users could trigger a crash of mongod primaries during promotion to sharded

    Affected:
    >=8.2.0,<8.2.2
    Fixed in:
    8.2.2
    Source:
    OSV source · Advisory
  • CVE-2026-4358

    Memory safety issues in slot-based execution hash table spill

    Affected:
    >=8.2.0,<8.2.6
    Fixed in:
    8.2.6
    Source:
    OSV source · Advisory
  • CVE-2026-4148

    ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators

    Affected:
    >=8.3.0-rc1,<8.2.6
    Fixed in:
    8.2.6
    Source:
    OSV source · Advisory
  • CVE-2026-4147

    Stack memory disclosure in filemd5 command

    Affected:
    >=8.3.0-rc1,<8.2.6
    Fixed in:
    8.2.6
    Source:
    OSV source · Advisory
  • CVE-2026-25613

    An unsafe cast in the MongoDB query planner can result in a segmentation fault.

    Affected:
    >=8.2.0,<8.2.4
    Fixed in:
    8.2.4
    Source:
    OSV source · Advisory
  • CVE-2026-1849

    Mongod can run out of stack memory when expressions create deeply nested documents

    Affected:
    >=8.2.0,<8.2.2
    Fixed in:
    8.2.2
    Source:
    OSV source · Advisory
  • CVE-2026-1850

    An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification

    Affected:
    >=8.2.0,<8.2.4
    Fixed in:
    8.2.4
    Source:
    OSV source · Advisory
  • CVE-2026-25609

    profile command may permit unauthorized configuration

    Affected:
    >=8.2.0,<8.2.4
    Fixed in:
    8.2.4
    Source:
    OSV source · Advisory
  • CVE-2026-1848

    Connections received from the proxy port may not count towards total accepted connections

    Affected:
    >=8.2.0,<8.2.4
    Fixed in:
    8.2.4
    Source:
    OSV source · Advisory
  • CVE-2026-1847

    MongoDB Server may crash when inserting large documents

    Affected:
    >=8.2.0,<8.2.4
    Fixed in:
    8.2.4
    Source:
    OSV source · Advisory
  • CVE-2025-14345

    Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server

    Affected:
    >=8.3.0-alpha0,<8.2.2
    Fixed in:
    8.2.2
    Source:
    OSV source · Advisory

Latest release

No releases recorded for this line.

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: MongoDB 8.0.

Version comparison

Compact comparison against the nearest relevant release lines.

8.28.0
Statusend of lifestandard support
Latest release8.0.29
EOLJul 2026Oct 2029
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
0
Lifecycle periods
2
EOL
Known
Provenance records
3
Data last checked
1 Sept 2026
Latest source update
1 Sept 2026

Other MongoDB versions