Update dependency mongodb to v5.8.0 [SECURITY] - #147
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
January 23, 2025 21:34
6e0fac5 to
2814277
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
March 3, 2025 12:50
2814277 to
46166a4
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
April 8, 2025 10:49
46166a4 to
4f76b03
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
April 24, 2025 10:13
4f76b03 to
57742d8
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
June 22, 2025 15:34
57742d8 to
31a4e29
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
August 10, 2025 13:50
31a4e29 to
bb127bd
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
October 21, 2025 20:37
bb127bd to
c095a19
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
December 31, 2025 16:05
c095a19 to
d9cac2a
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
January 19, 2026 18:08
d9cac2a to
2f1f4d8
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
February 12, 2026 10:51
2f1f4d8 to
c47015b
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
2 times, most recently
from
March 30, 2026 21:43
c47015b to
a7d7d78
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
2 times, most recently
from
April 27, 2026 22:18
a7d7d78 to
32acd44
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
May 12, 2026 12:42
32acd44 to
f21110d
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
2 times, most recently
from
May 23, 2026 16:59
f21110d to
d31834a
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
July 12, 2026 11:10
d31834a to
08cb05f
Compare
renovate
Bot
force-pushed
the
renovate/server-npm-mongodb-vulnerability
branch
from
July 30, 2026 16:15
08cb05f to
2925ed3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.6.0→5.8.0MongoDB Driver may publish events containing authentication-related data
CVE-2021-32050 / GHSA-vxvm-qww3-2fh7
More information
Details
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Severity
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mongodb/node-mongodb-native (mongodb)
v5.8.0Compare Source
The MongoDB Node.js team is pleased to announce version 5.8.0 of the
mongodbpackage!Release Notes
The
AutoEncrypterinterface has been deprecatedThe
AutoEncrypterinterface was used internally but accidentally made public in the 4.x version of the driver. It is now deprecated and will be made internal in the next major release.Kerberos support for 1.x and 2.x
Moves the kerberos dependency back to
^1.0.0 || ^2.0.0to indicate support for both 1.x and 2.x. Support for 1.x is removed in 6.0.Fixed accidental deprecation warning
Because of internal options handling, a deprecation was emitted for
tlsCertificateFilewhen usingtlsCertificateKeyFile. That has been corrected.Remove credential availability on
ConnectionPoolCreatedEventIn order to avoid mistakenly printing credentials the
ConnectionPoolCreatedEventwill replace the credentials option with an empty object. The credentials are still accessble via MongoClient options:client.options.credentials.Features
AutoEncrypterinterface (#3764) (9bb0d95)@aws-sdk/credential-providersversion to 3.188.0 andzstdto^1.0.0(#3821) (39ff81d)Bug Fixes
Documentation
We invite you to try the
mongodblibrary immediately, and report any issues to the NODE project.v5.7.0Compare Source
Features
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.