Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash

CVE Details

Basic Information

Title Certain Queries with Duplicate _id Fields May Cause MongoDB Server to Crash
Type cve
Published 2025-07-07T15:59:01.902Z
Modified 2025-07-07T16:13:48.353Z

Product Information

Vendor MongoDB Inc
Product MongoDB Server
Version 8.1

CVSS Information

Base Score 6.5 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Analysis

AI Description A vulnerability in MongoDB Server allows authorized users to cause a denial of service by issuing queries with duplicate _id fields, potentially crashing the server. This issue is specific to version 8.1.0.
AI Severity Medium
AI Vendor MongoDB Inc
AI Product MongoDB Server
AI Version 8.1.0

Affected Products

  • MongoDB Inc MongoDB Server 8.1

Additional Information

CWE List CWE-843
Source mongodb

Description

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and cause Denial of Service. This issue affects MongoDB Server v8.1 version 8.1.0.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.