CNNVD-202509-717 Information

CNNVD ID

CNNVD-202509-717

CVE-2025-10061

  • CNNVD Published: 2025-09-05

Description (Chinese)

MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server 6.0.25之前版本、7.0.22之前版本、8.0.12之前版本和8.1.2之前版本存在安全漏洞,该漏洞源于$group操作中累加器函数处理不当,可能导致拒绝服务攻击。

Description (English)

MongoDB Server is an open-source NoSQL database for MongoDB in the United States. The database provides a collection-oriented memory, dynamic queries, data replication and automatic downtime transfer. There is a security loophole in MongoDB Server 6.0.25, 7.0.22, 8.0.12 and 8.1.2, which stems from the inappropriate handling of the add-on function in the $[group operation, which may lead to a denial of service attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

MongoDB

Published

2025-09-05

Last Modified

2026-02-24

References

https://jira.mongodb.org/browse/SERVER-99616 https://access.redhat.com/security/cve/cve-2025-10061

Patch

https://jira.mongodb.org/browse/SERVER-99616

Share on: