CVE-2025-12119Expired Pointer Dereference in Mongodb C Driver

Severity
6.9MEDIUMNVD
EPSS
0.0%
top 99.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateNov 19

Description

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDmongodb/c_driver1.9.01.30.6+1
NVDmongodb/php_driver< 1.21.2
Packagistmongodb/mongodb-extension< 1.21.2
CVEListV5mongodb/c_driver1.9.01.30.5+1
CVEListV5mongodb/php_driver2.1.2

🔴Vulnerability Details

4
OSV
MongoDB driver extension affected by mongoc_bulk_operation_t's read of invalid memory2025-11-19
GHSA
MongoDB driver extension affected by mongoc_bulk_operation_t's read of invalid memory2025-11-19
CVEList
Bulk write with options may read invalid memory2025-11-18
OSV
CVE-2025-12119: A mongoc_bulk_operation_t may read invalid memory if large options are passed2025-11-18

📋Vendor Advisories

1
Debian
CVE-2025-12119: mongo-c-driver - A mongoc_bulk_operation_t may read invalid memory if large options are passed.2025
CVE-2025-12119 — Expired Pointer Dereference in Mongodb | cvebase