PT-2025-28209 · Mongodb · Mongodb Server+1

Published

2025-03-20

·

Updated

2025-12-19

·

CVE-2025-7259

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: MongoDB Server version 8.1.0
Description: An authorized user can issue queries with duplicate id fields, leading to unexpected behavior in MongoDB Server, which may result in a crash. This issue can only be triggered by authorized users and causes Denial of Service.
Recommendations: For MongoDB Server version 8.1.0, update to a version that fixes this issue to prevent Denial of Service attacks by authorized users issuing queries with duplicate id fields.

Fix

DoS

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-09088
BIT-MONGODB-2025-14847
BIT-MONGODB-2025-7259
CVE-2025-7259

Affected Products

Mongodb Server
Mongodb