CVE-2025-7259

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-102693 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:mongodb:8.1.0:*:*:*:-:*:*:*

History

03 Oct 2025, 20:50

Type Values Removed Values Added
CPE cpe:2.3:a:mongodb:mongodb:8.1.0:*:*:*:-:*:*:*
First Time Mongodb mongodb
Mongodb
References () https://jira.mongodb.org/browse/SERVER-102693 - () https://jira.mongodb.org/browse/SERVER-102693 - Issue Tracking, Vendor Advisory

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Un usuario autorizado puede ejecutar consultas con campos _id duplicados, lo que provoca un comportamiento inesperado en MongoDB Server y puede provocar un bloqueo. Este problema solo lo pueden activar usuarios autorizados y causa una denegación de servicio. Afecta a MongoDB Server v8.1 (versión 8.1.0).

07 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 16:15

Updated : 2025-10-03 20:50


NVD link : CVE-2025-7259

Mitre link : CVE-2025-7259

CVE.ORG link : CVE-2025-7259


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')