VulnSea

mongodb_entity_framework_core_provider vulnerabilities

CVEs whose affected-version data names the mongodb_entity_framework_core_provider package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-92757Medium· 5.5
5d ago

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.05%via NVD
CVE-2026-92756Medium· 5.5
5d ago

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.05%via NVD
CVE-2026-92758Medium· 5.5
5d ago

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.11%via NVD
mongodb_entity_framework_core_provider vulnerabilities (CVEs) · VulnSea