CVE-2025-13644

EUVD-2025-199552
MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
mongodbCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
mongodbmongodb
7.0.0 ≤
𝑥
< 7.0.26
mongodbmongodb
8.0.0 ≤
𝑥
< 8.0.13
mongodbmongodb
8.1.0 ≤
𝑥
< 8.1.2
mongodbmongodb
8.2.0:alpha
mongodbmongodb
8.2.0:alpha0
mongodbmongodb
8.2.0:alpha1
mongodbmongodb
8.2.0:alpha2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mongodb
bionic
not-affected
focal
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected