CVE-2025-13507

MEDIUM

MongoDB <7.0.26-8.0.16-8.2.1 - Memory Corruption

Title source: llm
STIX 2.1

Description

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (1)
mongodb/mongodb 7.0.0 - 7.0.26
Published Nov 25, 2025
Tracked Since Feb 18, 2026