CVE-2025-12657

MEDIUM

Mongo - Memory Corruption

Title source: llm
STIX 2.1

Description

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

Scores

CVSS v3 5.0
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
mongodb/mongodb 6.0.0 - 7.0.22
Published Nov 03, 2025
Tracked Since Feb 18, 2026