We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3083

Malformed MongoDB wire protocol messages may cause mongos to crash



Description

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16

Reserved 2025-04-01 | Published 2025-04-01 | Updated 2025-04-01 | Assigner mongodb


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-248: Uncaught Exception

Product status

Default status
unaffected

5.0 before 5.0.31
affected

6.0 before 6.0.20
affected

7.0. before 7.0.16
affected

References

jira.mongodb.org/browse/SERVER-103152

cve.org (CVE-2025-3083)

nvd.nist.gov (CVE-2025-3083)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3083

Support options

Helpdesk Chat, Email, Knowledgebase