NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #1368 by repository stars
The MongoDB Kotlin Driver
Last release 12 days ago
26 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Some releases are documented
notes for 13 of 42 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
51 releases · first in 2023
One column per quarter.
build(deps): bump testing/resources/specifications from 92b3c0b to 529a2dd by @apmasell in #2061
92b3c0b to 529a2dd by @apmasell in #2061Full Changelog: r5.12.0...r5.13.0
Please refer to https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8Java Driver 5.13.0 (September 25, 2026) Latest
Latest
Compare
JAVA-6231 build(deps): bump testing/resources/specifications from d4d0cdf to 92b3c0b by @dependabot [bot] in #2039
d4d0cdf to 92b3c0b by @dependabot[bot] in #2039Full Changelog: r5.11.0...r5.12.0
Added support for MongoDB 9.0's Intelligent Workload Management (IWM). The driver now gracefully handles write-blocking scenarios and optimizes connection establishment during high-load conditions to maintain application availability.
Please refer to https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8Java Driver 5.12.0 (September 17, 2026)
Compare
See JAVA-6283 / CVE-2026-88033 ]
Warning
Starting from driver version 3.3.0, an improper neutralization of a query operator in the GridFS delete methods allowed unintended data deletion.
See JAVA-6283 / CVE-2026-88033]
Upgrade reactive/sync driver version to 5.11.1 or later.
If you cannot upgrade, applications using older driver versions should call another delete overload delete(ObjectId). The driver constructs the BsonObjectId internally from a typed value, so no document can reach the filter.
Warning
Starting from driver version 4.2.0, cancelling or timing out an encrypted operation while the driver fetches cloud KMS credentials makes it call into freed native memory, crashing or corrupting the application.
See JAVA-6266 / CVE-2026-88032
Upgrade both reactive driver and mongodb-crypt to version 5.11.1 or later.
Full Changelog: r5.11.0...r5.11.1
Java Driver 5.11.1 (September 10, 2026)
Compare
Java 6173 CSFLE/QE Support for HTTP Proxies by @strogiyotec in #2043
SSLContext configured forSSLSocket and the driver layers the KMS host's TLS session on top of it.Code example uses only the JDK API , so no HTTP client dependency is required. If you use your own HTTP client, it must return the tunnelled socket without negotiating TLS with the KMS host
First define the callback
private static final String PROXY_HOST = "proxy.example.com";
private static final int PROXY_PORT = 8080;
private static final int TIMEOUT_MILLIS = 10_000;
// Routes every KMS request through an HTTP proxy using the HTTP CONNECT method
// refer to the docs https://www.rfc-editor.org/info/rfc9110/#section-9.3.6
KmsConnectCallback proxyCallback = context -> {
Socket socket = new Socket();
try {
// 1. Connect to the proxy, not to the KMS host.
socket.connect(new InetSocketAddress(PROXY_HOST, PROXY_PORT), TIMEOUT_MILLIS);
socket.setSoTimeout(TIMEOUT_MILLIS);
// 2. Ask the proxy to open a tunnel to the KMS host the driver wants to reach. Only the
// driver knows which host that is, so always take it from the context rather than
// hard-coding it.
String target = context.getHost() + ":" + context.getPort();
String connectRequest = "CONNECT " + target + " HTTP/1.1\r\n"
+ "Host: " + target + "\r\n"
// If the proxy requires authentication, add the appropriate header, for example:
// + "Proxy-Authorization: Basic " + base64("user:password") + "\r\n"
+ "\r\n";
socket.getOutputStream().write(connectRequest.getBytes(StandardCharsets.US_ASCII));
// 3. Check the proxy accepted the tunnel before handing the socket back.
checkProxyAcceptedTunnel(socket.getInputStream());
} catch (IOException | RuntimeException e) {
// The driver never received this socket, so it cannot close it for you.
socket.close();
throw e;
}
// 4. Return the tunnelled socket. The driver now performs its own TLS handshake with the KMS
// host over it, verifying the KMS host's certificate. Do not negotiate TLS with the KMS
// host yourself.
return socket;
};
// Reads the proxy's response to CONNECT and fails unless it is 2xx.
static void checkProxyAcceptedTunnel(InputStream in) throws IOException {
StringBuilder response = new StringBuilder();
int b;
while (response.indexOf("\r\n\r\n") < 0 && (b = in.read()) != -1) {
response.append((char) b);
}
String statusLine = response.toString().split("\r\n", 2)[0];
if (!statusLine.startsWith("HTTP/1.1 2") && !statusLine.startsWith("HTTP/1.0 2")) {
throw new IOException("Proxy refused the CONNECT request: " + statusLine);
}
}
Then use this callback to configure the ClientEncryption
ClientEncryptionSettings settings = ClientEncryptionSettings.builder()
.keyVaultMongoClientSettings(keyVaultClientSettings)
.keyVaultNamespace("keyvault.datakeys")
.kmsProviders(kmsProviders)
.kmsConnectCallback(proxyCallback)
.build();
Or using automatic encryption
AutoEncryptionSettings settings = AutoEncryptionSettings.builder()
.keyVaultNamespace("keyvault.datakeys")
.kmsProviders(kmsProviders)
.kmsConnectCallback(proxyCallback)
.build();
Full Changelog: r5.10.0...r5.11.0
Included the fix for CVE-2026-18710 / JAVA-6266 , where ProxySettings.toString() rendered the SOCKS5 proxy username and password into application logs…
$scoreFusion hybrid search stage for combining and normalizing the scores of multiple search pipelines (MongoDB 8.2+) #2024 by @nhachicha$score aggregation stage, with normalization, weighting, and score details (MongoDB 8.2+) #2023 by @strogiyotec$vectorSearch support for nested embeddings and arrays of embeddings via parentFilter and nestedOptions #2026 by @rozza@Beta from SearchOptions and VectorSearchOptions in the Java and Scala drivers #2026 by @rozzaByteArray data class fields as BSON Binary, and added an opt-in ByteArray BSON Binary serializer for bson-kotlinx #2019 by @rozzaProxySettings.toString() rendered the SOCKS5 proxy username and password into application logs. First shipped in 5.9.2 #2035 by @strogiyotecByteArray fields in Kotlin data classes are once again encoded as BSON Binary rather than a BSON array of int32, restoring the behavior from before 5.1.3. Decoding accepts both forms, so documents written by 5.1.3–5.9.x still read back correctly, but newly written documents change BSON type. Review any non-driver consumers of those fields before upgrading. See JAVA-6224Please refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.9.0...r5.10.0
Warning Starting from driver version 4.11.0, ProxySettings.toString() included the SOCKS5 proxy username and password in application logs.
Warning
Starting from driver version 4.11.0, ProxySettings.toString() included the SOCKS5 proxy username and password in application logs.
See JAVA-6266 / CVE-2026-18710
The username and password are no longer included in toString() starting in this release.
If you cannot upgrade, set the org.mongodb.driver.client logger to WARN or higher to suppress the client-construction message. We do not recommend this as a long-term measure: it silences diagnostic information that is valuable for support, and it does not remove credentials already written to existing logs.
Full Changelog: r5.9.1...r5.9.2
Backport: Resolve forwarded type arguments across POJO hierarchy edges by @vbabanin in #2020
Please refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.9.0...r5.9.1
build(deps): bump testing/resources/specifications from b519824 to 25bee54 by @dependabot [bot] in #1984
b519824 to 25bee54 by @dependabot[bot] in #1984MongoClient.getTimeout always returning null by @stIncMale in #2009Please refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.8.0...r5.9.0
Fix reactive streams MongoClient.getTimeout always returning null by @stIncMale in #2011
MongoClient.getTimeout always returning null by @stIncMale in #2011Please refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.8.0...r5.8.1
Added typed builder API for vector search index definitions #1960 by @rozza
$rerank aggregation stage support (MongoDB 8.3 / Atlas) #1963 by @rozzavectorSearch operator support for the $search pipeline stage #1962 by @rozzastoredSource support for vector search indexes and returnStoredSource for $vectorSearch queries #1977 by @rozzaBinaryVector and VectorSearchQuery vectorSearch overloads to the Scala driver #1986 by @rozzaRawBsonDocument encode and decode by eliminating intermediate allocations #1988 by @rozzaMongodbObservation and MongodbObservationContext by @rozzalibmongocrypt to 1.18.1 #1983 by @strogiyotecAGENTS.md for AI coding agent support across all modules by @rozzapublish.sh #1958 by @rozzaNamespaceExists test failure #1956 by @nhachichaRetryState creation as preliminary backpressure work #1961 by @stIncMaleRetryState.isLastAttempt private and simplified code #1967 by @stIncMalePlease refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.7.0...r5.8.0
JAVA-6189 - Added Scala 3 to publish.sh by @rozza in #1957
Important A future minor release will raise the minimum supported MongoDB Server version from 4.2 to 4.4. This is in accordance with MongoDB Software
Important
A future minor release will raise the minimum supported MongoDB Server version from 4.2 to 4.4. This is in accordance with MongoDB Software Lifecycle Schedules. Support for MongoDB Server 4.2 will be dropped in a future release!
TODO-JAVA-6126 to inform readers that the problem is known by @stIncMale in #1910bb9dddd to 0535e65 by @dependabot[bot] in #19150535e65 to c3c82b6 by @dependabot[bot] in #1930com.mongodb.client.FailPoint.enable by @stIncMale in #1931c3c82b6 to 7039e69 by @dependabot[bot] in #1945Please refer to https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.7.0-beta1...r5.7.0
Updated Snappy for latest security fixes #1868
Add Micrometer/OpenTelemetry tracing support to the reactive-streams
(Micrometer / OpenTelemetry) #1898
Improved client-side timeout handling to better account for RTT variations #1793
Fixed RawBsonDocument encoding performance regression by restoring optimized codec path #1888
Fixed Netty ByteBuf reference counting and reverted read-only change that could cause leaks during logging #1891
Updated BSON/spec tests and improved Extended JSON alignment #1883
Added SARIF reporting and CI improvements #1869
Temporarily disabled large encryption tests on mongocryptd for CI stability #1872
Please refer to https://www.mongodb.com/docs/drivers/java/sync/v5.4/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.7.0-beta0...r5.7.0-beta1
Java Driver 5.7.0-beta1 (February 26, 2026) Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
AsyncCommandCursor.getMoreLoop() held a pool connection across empty getMore responses on tailable cursors, exhausting the connection pool when idle c
Please refer to https://www.mongodb.com/docs/drivers/java/sync/v5.4/security/validate-signatures/ for the full procedure.
To download and import the public key for verifying signatures, execute
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8
Full Changelog: r5.6.4...r5.6.5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →