CVE-2025-13507

MEDIUM

MongoDB <7.0.26-8.0.16-8.2.1 - Memory Corruption

Title source: llm
STIX 2.1

Description

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (1)
mongodb/mongodb 7.0.0 - 7.0.26
Published Nov 25, 2025
Tracked Since Feb 18, 2026