PT-2025-28209 · Mongodb · Mongodb Server+1

CVE-2025-7259

·

Published

2025-03-20

·

Updated

2025-12-19

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: MongoDB Server version 8.1.0
Description: An authorized user can issue queries with duplicate id fields, leading to unexpected behavior in MongoDB Server, which may result in a crash. This issue can only be triggered by authorized users and causes Denial of Service.
Recommendations: For MongoDB Server version 8.1.0, update to a version that fixes this issue to prevent Denial of Service attacks by authorized users issuing queries with duplicate id fields.

Exploit

Fix

DoS

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09088
BIT-MONGODB-2025-14847
BIT-MONGODB-2025-7259
CVE-2025-7259

Affected Products

Mongodb Server
Mongodb