MongoDB 8.3.7
MongoDB 8.3.7 — Released July 22, 2026. This patch release addresses several security vulnerabilities and includes reliability improvements for the MongoDB 8.3 series.
Security Fixes
MongoDB 8.3.7 resolves the following CVEs:
- CVE-2026-9737
- CVE-2026-13055
- CVE-2026-13056 — A user with read access can cause a denial of service
- CVE-2026-13057
- CVE-2026-13058
- CVE-2026-13059
- CVE-2026-13060
- CVE-2026-13061
- CVE-2026-13062
- CVE-2026-13063
- CVE-2026-13064
Reliability Improvements
Beyond the security patches, this release includes hardening measures across the server, including improvements to query execution stability and storage engine resilience in edge-case scenarios.
Upgrade Advisory
All MongoDB 8.3 users are strongly recommended to upgrade to 8.3.7 at the earliest opportunity, particularly those operating in multi-tenant or internet-facing environments where the addressed CVEs pose elevated risk.
Compatibility Notes
MongoDB 8.3.7 is a drop-in replacement for 8.3.4, 8.3.5, and 8.3.6. No schema changes, driver upgrades, or configuration modifications are required. Standard rolling upgrade procedures apply for replica sets and sharded clusters.
Previous 8.3.x Highlights
The MongoDB 8.3 series introduced up to 45% faster reads and 35% faster writes compared to earlier releases, along with expanded aggregation expressions, native type comparison improvements, and enhanced shard management commands.