Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.
History

Tue, 25 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 05:00:00 +0000

Type Values Removed Values Added
Description Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.
Title Time-series operations may cause internal BSON size limit to be exceed
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published: 2025-11-25T04:52:47.714Z

Updated: 2025-11-25T16:47:41.290Z

Reserved: 2025-11-21T16:20:52.636Z

Link: CVE-2025-13507

cve-icon Vulnrichment

Updated: 2025-11-25T16:47:36.653Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-25T05:16:09.090

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-13507

cve-icon Redhat

No data.