CVE 7.1 HIGH

Time-series operations may cause internal BSON size limit to be exceed_CVE-2025-13507

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination.
This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.

Basic Information

ID CVE-2025-13507
Source mongodb
Published Nov 25, 2025 at 04:52

Affected Product

Vendor MongoDB Inc.
Product MongoDB Server
Version 7.0
Affected Versions MongoDB Inc. MongoDB Server 7.0
MongoDB Inc. MongoDB Server 8.0
MongoDB Inc. MongoDB Server 8.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.