An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.
History

Mon, 07 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Description An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.
Title Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash
First Time appeared Mongodb
Mongodb mongodb
Weaknesses CWE-843
CPEs cpe:2.3:a:mongodb:mongodb:8.1.0:*:*:*:*:*:*:*
Vendors & Products Mongodb
Mongodb mongodb
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published: 2025-07-07T15:59:01.902Z

Updated: 2025-07-07T16:13:48.353Z

Reserved: 2025-07-07T15:05:32.437Z

Link: CVE-2025-7259

cve-icon Vulnrichment

Updated: 2025-07-07T16:13:45.460Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-07T16:15:30.440

Modified: 2025-07-08T16:18:34.923

Link: CVE-2025-7259

cve-icon Redhat

No data.