CVE-2025-6710Uncontrolled Recursion in INC Mongodb Server

Severity
7.5HIGHNVD
EPSS
0.1%
top 83.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26

Description

MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5mongodb_inc/mongodb_server6.06.0.21+2
NVDmongodb/mongodb6.0.06.0.21+2

🔴Vulnerability Details

3
GHSA
GHSA-p332-57gq-w6hx: MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted level2025-06-26
OSV
CVE-2025-6710: MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted level2025-06-26
CVEList
Pre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDB2025-06-26
CVE-2025-6710 — Uncontrolled Recursion | cvebase