MongoDB 8.2 lifecycle
Current status
MongoDB 8.2 reached end of life on 31 Jul 2026. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Official lifecycle source: MongoDB Server lifecycle schedule
- Support phase
- end of life
- End of life
- 31 Jul 2026
- Latest release
- —
- Released
- —
At a glance
- Version line
- 8.2
- Initial release
- 1 Sept 2025
- Lifecycle phase
- end of life
- Latest stable
- —
- Latest release date
- —
- EOL
- 31 Jul 2026
- Risk
- high
- Releases tracked
- 0
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
Release
1 Sept 2025
standard support
1 Sept 2025 → 31 Jul 2026
Source: MongoDB Server lifecycle schedule
end of lifecurrent
31 Jul 2026 → —
Source: MongoDB Server lifecycle schedule
MongoDB 8.2 reached end of life on 31 Jul 2026. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Security
Advisories affecting MongoDB 8.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 1
- Highest CVSS
- 7.5
- CVE-2025-14847Known exploited
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
Zlib compressed protocol header length confusion may allow memory read
- CISA KEV:
- listed · added 2025-12-29 · due 2026-01-19
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-130
- Affected:
- >=8.2.0,<8.2.3
- Fixed in:
- 8.2.3
- CVE-2026-8063
Post-auth null pointer dereference when aggregating against a view with empty search pipeline
- Affected:
- >=8.2.0,<8.2.7
- Fixed in:
- 8.2.7
- Source:
- OSV source · Advisory
- CVE-2026-6915
Flaw in the updateUser Command May Allow Unauthorized Configuration Change
- Affected:
- >=8.2.0,<8.2.7
- Fixed in:
- 8.2.7
- Source:
- OSV source · Advisory
- CVE-2026-6914
MD5 checksum creation may cause availability loss
- Affected:
- >=8.1.0,<8.2.7
- Fixed in:
- 8.2.7
- Source:
- OSV source · Advisory
- CVE-2026-5170
Users could trigger a crash of mongod primaries during promotion to sharded
- Affected:
- >=8.2.0,<8.2.2
- Fixed in:
- 8.2.2
- Source:
- OSV source · Advisory
- CVE-2026-4358
Memory safety issues in slot-based execution hash table spill
- Affected:
- >=8.2.0,<8.2.6
- Fixed in:
- 8.2.6
- Source:
- OSV source · Advisory
- CVE-2026-4148
ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators
- Affected:
- >=8.3.0-rc1,<8.2.6
- Fixed in:
- 8.2.6
- Source:
- OSV source · Advisory
- CVE-2026-4147
Stack memory disclosure in filemd5 command
- Affected:
- >=8.3.0-rc1,<8.2.6
- Fixed in:
- 8.2.6
- Source:
- OSV source · Advisory
- CVE-2026-25613
An unsafe cast in the MongoDB query planner can result in a segmentation fault.
- Affected:
- >=8.2.0,<8.2.4
- Fixed in:
- 8.2.4
- Source:
- OSV source · Advisory
- CVE-2026-1849
Mongod can run out of stack memory when expressions create deeply nested documents
- Affected:
- >=8.2.0,<8.2.2
- Fixed in:
- 8.2.2
- Source:
- OSV source · Advisory
- CVE-2026-1850
An authorized user may disable the MongoDB server by issuing a certain type of complex query due to boolean expression simplification
- Affected:
- >=8.2.0,<8.2.4
- Fixed in:
- 8.2.4
- Source:
- OSV source · Advisory
- CVE-2026-25609
profile command may permit unauthorized configuration
- Affected:
- >=8.2.0,<8.2.4
- Fixed in:
- 8.2.4
- Source:
- OSV source · Advisory
- CVE-2026-1848
Connections received from the proxy port may not count towards total accepted connections
- Affected:
- >=8.2.0,<8.2.4
- Fixed in:
- 8.2.4
- Source:
- OSV source · Advisory
- CVE-2026-1847
MongoDB Server may crash when inserting large documents
- Affected:
- >=8.2.0,<8.2.4
- Fixed in:
- 8.2.4
- Source:
- OSV source · Advisory
- CVE-2025-14345
Cross-Shard Failovers May Lead to Partial Transaction Commit in MongoDB Server
- Affected:
- >=8.3.0-alpha0,<8.2.2
- Fixed in:
- 8.2.2
- Source:
- OSV source · Advisory
Latest release
No releases recorded for this line.
Should I use this version?
Not recommended for new deployments
Upgrade to a currently supported release line. Recommended target: MongoDB 8.0.
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- MongoDB Server lifecycle schedulefirst party · high confidence
Official source: https://www.mongodb.com/legal/support-policy/lifecycles
Last verified 1 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- MongoDB Server lifecycle schedulefirst party · high confidence
Official source: https://www.mongodb.com/legal/support-policy/lifecycles
Last verified 1 Sept 2026
- MongoDB Server release notesfirst party
Official source: https://www.mongodb.com/docs/manual/release-notes/
Verification time not recorded
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 0
- Lifecycle periods
- 2
- EOL
- Known
- Provenance records
- 3
- Data last checked
- 1 Sept 2026
- Latest source update
- 1 Sept 2026
