CVE-2025-13643

EUVD-2025-199550
A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
mongodbCNA
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
mongodbmongodb
7.0.0 ≤
𝑥
< 7.0.26
mongodbmongodb
8.0.0 ≤
𝑥
< 8.0.14
mongodbmongodb
8.2.0:alpha
mongodbmongodb
8.2.0:alpha0
mongodbmongodb
8.2.0:alpha1
mongodbmongodb
8.2.0:alpha2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mongodb
bionic
deferred
focal
deferred
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected