CVE-2025-7259Type Confusion in INC Mongodb Server

CWE-843Type Confusion4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 70.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7

Description

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5mongodb_inc/mongodb_server8.18.1.0
NVDmongodb/mongodb8.1.0

🔴Vulnerability Details

3
GHSA
GHSA-xg2f-3225-7hxr: An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash2025-07-07
CVEList
Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash2025-07-07
OSV
CVE-2025-7259: An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash2025-07-07
CVE-2025-7259 — Type Confusion in INC Mongodb Server | cvebase