PT-2025-47989 · Mongodb+1 · Mongodb Server+2

Published

2025-11-25

·

Updated

2025-12-19

·

CVE-2025-13507

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to 7.0.26 MongoDB Server versions prior to 8.0.16 MongoDB Server versions prior to 8.2.1
Description An issue exists in the time series processing logic where inconsistent object size validation can lead to the processing of oversized BSON documents. This can cause an assertion failure and terminate the process.
Recommendations Update MongoDB Server to version 7.0.26 or later. Update MongoDB Server to version 8.0.16 or later. Update MongoDB Server to version 8.2.1 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-00270
BIT-MONGODB-2025-13507
CVE-2025-13507

Affected Products

Mongodb Server
Mongodb
Red Os