PT-2025-28209 · Mongodb · Mongodb Server+1
Published
2025-03-20
·
Updated
2025-12-19
·
CVE-2025-7259
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
MongoDB Server version 8.1.0
Description:
An authorized user can issue queries with duplicate
id fields, leading to unexpected behavior in MongoDB Server, which may result in a crash. This issue can only be triggered by authorized users and causes Denial of Service.Recommendations:
For MongoDB Server version 8.1.0, update to a version that fixes this issue to prevent Denial of Service attacks by authorized users issuing queries with duplicate
id fields.Fix
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Server
Mongodb