Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-13644


MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2


Published

2025-11-25T06:15:45.753

Last Modified

2025-12-11T23:19:48.973

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mongodb mongodb < 7.0.26 Yes
Application mongodb mongodb < 8.0.13 Yes
Application mongodb mongodb < 8.1.2 Yes
Application mongodb mongodb 8.2.0 Yes
Application mongodb mongodb 8.2.0 Yes
Application mongodb mongodb 8.2.0 Yes
Application mongodb mongodb 8.2.0 Yes

References