← Back

CVE-2025-12657

nvd nist
Published: Nov 3, 2025Modified: Dec 12, 2025

JSON object

Loading...
5.9
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

Affected (2)

Products: Mongodb: Mongodb
1 product
Mongodb
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Mongodb
From 6.0.0 to 7.0.22
From 8.0.0 to 8.0.10

References (1)

Source: cna@mongodb.com
Vendor Advisory

Timeline

No history available yet.