PT-2025-42794 · Mongodb+1 · Mongodb Server+2
Published
2025-10-20
·
Updated
2025-12-06
·
CVE-2025-11979
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB Server versions prior to 7.0.25
MongoDB Server versions prior to 8.0.15
MongoDB Server version 8.2.0
Description
An authorized user may crash the MongoDB server by causing a buffer over-read. This can occur by issuing a Data Definition Language (DDL) operation while queries are being issued, under specific conditions. The issue is related to a use-after-free condition in the query planner, potentially leading to a crash or undefined behavior.
Recommendations
Update MongoDB Server to version 7.0.25 or later.
Update MongoDB Server to version 8.0.15 or later.
Update MongoDB Server to version 8.2.0 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Server
Mongodb
Red Os