PT-2025-42794 · Mongodb+1 · Mongodb Server+2

Published

2025-10-20

·

Updated

2025-12-06

·

CVE-2025-11979

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to 7.0.25 MongoDB Server versions prior to 8.0.15 MongoDB Server version 8.2.0
Description An authorized user may crash the MongoDB server by causing a buffer over-read. This can occur by issuing a Data Definition Language (DDL) operation while queries are being issued, under specific conditions. The issue is related to a use-after-free condition in the query planner, potentially leading to a crash or undefined behavior.
Recommendations Update MongoDB Server to version 7.0.25 or later. Update MongoDB Server to version 8.0.15 or later. Update MongoDB Server to version 8.2.0 or later.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15582
BIT-MONGODB-2025-11979
CVE-2025-11979

Affected Products

Mongodb Server
Mongodb
Red Os