CVE-2025-12657

MEDIUM

MongoDB 6.0.0-7.0.21 - Denial of Service via KMIP Response Parser

Title source: llm
STIX 2.1

Description

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

References (1)

Core 1
Core References

Scores

CVSS v3 5.0
EPSS 0.0032
EPSS Percentile 23.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
mongodb/mongodb 6.0.0 - 7.0.22
Published Nov 03, 2025
Tracked Since Feb 18, 2026