CVE-2025-11979
Last modified
CVE-2025-11979 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to 8.0.15, and MongoDB Server version 8.2.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 7.0.0, < 7.0.25 |
| Mongodb | Mongodb | >= 8.0.0, < 8.0.15 |
References
- https://jira.mongodb.org/browse/SERVER-105873Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11979?
How severe is CVE-2025-11979?
How do I fix CVE-2025-11979?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11972The Tag, Category, and Taxonomy Manager – AI Autotagger with…4.9
- CVE-2025-11973The 简数采集器 plugin for WordPress is vulnerable to Arbitrary Fi…4.9
- CVE-2025-11974GitLab has remediated an issue in GitLab CE/EE affecting all…6.5
- CVE-2025-11975The FuseWP – WordPress User Sync to Email List & Marketing A…4.3
- CVE-2025-11976The FuseWP – WordPress User Sync to Email List & Marketing A…4.3
- CVE-2025-11977The Happyforms – Form Builder for WordPress: Drag & Drop Con…6.6
- CVE-2025-1198An issue discovered in GitLab CE/EE affecting all versions f…5.3
- CVE-2025-11980The Quick Featured Images plugin for WordPress is vulnerable…4.9
- CVE-2025-11981The School Management System – WPSchoolPress plugin for Word…4.9
- CVE-2025-11983The WP Discourse plugin for WordPress is vulnerable to Infor…4.3
- CVE-2025-11984GitLab has remediated an issue in GitLab CE/EE affecting all…6.8
- CVE-2025-11985The Realty Portal plugin for WordPress is vulnerable to unau…8.8
Are you affected by CVE-2025-11979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
