CVE-2025-6712
Last modified
CVE-2025-6712 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal operations. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal operations. In scenarios where certain internal processes persist longer than anticipated, memory consumption can increase, potentially impacting server stability and availability. This issue affects MongoDB Server v8.0 versions prior to 8.0.10
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 8.0.0, < 8.0.10 |
References
- https://jira.mongodb.org/browse/SERVER-106751Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6712?
How severe is CVE-2025-6712?
How do I fix CVE-2025-6712?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6711An issue has been identified in MongoDB Server where unredac…4.9
- CVE-2025-67111An integer overflow in the RTPS protocol implementation of O…7.5
- CVE-2025-67112Use of a hard-coded AES-256-CBC key in the configuration bac…9.8
- CVE-2025-67113OS command injection in the CWMP client (/ftl/bin/cwmp) of S…9.8
- CVE-2025-67114Use of a deterministic credential generation algorithm in /f…9.8
- CVE-2025-67115A path traversal vulnerability in /ftl/web/setup.cgi in Smal…6.5
- CVE-2025-67124A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 uplo…6.8
- CVE-2025-67125A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern:…4.4
- CVE-2025-6713An unauthorized user may leverage a specially crafted aggreg…6.5
- CVE-2025-67133An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local a…7.5
- CVE-2025-67135Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm Sy…9.8
- CVE-2025-6714MongoDB Server's mongos component can become unresponsive to…7.5
Are you affected by CVE-2025-6712?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
