AWS Security ChangesHomeSearch

AWS documentdb: DocumentDB 8.0.2/5.0.2 release notes incl. collStats security fix

Service: documentdb · 2026-09-29 · Security-related high

File: documentdb/latest/devguide/release-notes.md · Type: authz

Summary

Adds release notes for Amazon DocumentDB 8.0.2 and 5.0.2 (new features, planner improvements, bug fixes) and a note that from 5.0.2/8.0.2 the engine version command returns engine version plus patch version as a single string. The 8.0.2 bug-fix list includes an explicit "Security fix for the collStats command."

Security assessment

The diff explicitly states a security fix was made to the collStats command, indicating a patched weakness (likely improper access control or information disclosure via collection statistics) in the database engine; no CVE or advisory identifier is referenced, and the rest of the entry is feature/version-numbering documentation.

Evidence

+  4. Security fix for the `collStats` command.

Diff

diff --git a/documentdb/latest/devguide/release-notes.md b/documentdb/latest/devguide/release-notes.md
index 5010cef2a..9053a4e60 100644
--- a//documentdb/latest/devguide/release-notes.md
+++ b//documentdb/latest/devguide/release-notes.md
@@ -19,0 +20,4 @@ You can determine the current Amazon DocumentDB engine patch version by running
+###### Note
+
+Starting with Amazon DocumentDB 5.0.2 and 8.0.2, this command returns the engine version and the engine patch version as a single string in the form ``engine-version`+`engine-patch-version``. For example, a cluster on Amazon DocumentDB 5.0.2 returns `5.0.2+3.0.12345`, and a cluster on 8.0.2 returns `8.0.2+4.0.12345`. Clusters on earlier versions return the engine patch version on its own, such as `3.0.12345`. For more information, see [Engine version numbering](./db-instance-maintain.html#engine-version-numbering).
+
@@ -41,0 +46,37 @@ Release notes for Amazon DocumentDB engine version 8.0 (MongoDB 8.0 compatibilit
+###### Amazon DocumentDB 8.0.2
+
+Date | Release notes  
+---|---  
+September 28, 2026 |  **Amazon DocumentDB 8.0.2 (Engine Version: 4.0.12042)** **New features and improvements**
+
+  1. Added support for the `$setWindowFields` aggregation stage and its window operators in Planner version 3.
+  2. Added support for the `$bucketAuto` aggregation stage in Planner version 3.
+  3. Added support for the `$facet` aggregation stage in Planner version 3.
+  4. Added support for the `$graphLookup` aggregation stage in Planner version 3.
+  5. Added support for correlated `$lookup` subqueries, including the concise correlated subquery syntax, with a subset of pipeline stages in Planner version 3.
+  6. Added support for the `$changeStreamSplitLargeEvent` aggregation stage.
+  7. Change streams now emit events for `createCollection` operations.
+  8. Change streams now emit events for `createIndex` operations.
+  9. Improved change stream write performance.
+  10. Added support for retryable writes.
+  11. Added support for the `reIndex` command on partial indexes.
+  12. Planner version 3 now supports index scans on `$expr` predicates.
+  13. Planner version 3 introduces multi-field Index Only Scans (IXONLYSCAN) for find queries. For more information, see [Index-only scans (covered queries)](./performance-index-only-scans.html).
+  14. Planner version 3 introduces Index Only Scans (IXONLYSCAN) for aggregation stages such as `$group`. For more information, see [Index-only scans (covered queries)](./performance-index-only-scans.html).
+  15. Performance optimization for `$count` and `countDocuments()` in Planner version 3.
+  16. Added support for incremental sort in Planner version 3. For more information, see [Incremental sort](./sort.html#sort-incremental-sort).
+  17. Improved plan selection for text index queries.
+  18. The explain plan for coalesced `$lookup` and `$unwind` stages now reflects the `includeArrayIndex` parameter.
+  19. Added index filter support across all commands.
+  20. The query planner now prioritizes unique indexes for equality (`$eq`) predicates.
+  21. Increased the truncation limit for aggregate commands in `currentOp` output.
+
+**Bug fixes**
+
+  1. Fixed a bug in the version 1 (default) query planner.
+  2. Fixed partial index expression text round-trip handling during Major Version Upgrade (MVU).
+  3. Fixed a profiler issue for fast count queries.
+  4. Security fix for the `collStats` command.
+
+  
+  
@@ -139,0 +181,20 @@ Release notes for Amazon DocumentDB engine version 5.0 (MongoDB 5.0 compatibilit
+###### Amazon DocumentDB 5.0.2
+
+Date | Release notes  
+---|---  
+September 28, 2026 |  **Amazon DocumentDB 5.0.2 (Engine Version: 3.0.23065)** **New features and improvements**
+
+  1. Added hidden index support for all index types (planner version 2 and above).
+  2. Support for the `min()` and `max()` cursor methods on the find command.
+  3. Added index filter support across all commands.
+  4. The query planner now prioritizes unique indexes for equality (`$eq`) predicates.
+  5. Increased the truncation limit for aggregate commands in `currentOp` output.
+
+**Bug fixes**
+
+  1. Fixed a bug in the version 1 (default) query planner.
+  2. Fixed partial index expression text round-trip handling during Major Version Upgrade (MVU).
+  3. Fixed a profiler issue for fast count queries.
+
+  
+