Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-11695


When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5


Published

2025-10-13T17:15:34.190

Last Modified

2025-12-04T21:36:42.340

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mongodb rust_driver < 3.2.5 Yes

References