jira.mongodb.org
https://jira.mongodb.org/browse/SERVER-114838 CVE-2026-25612
HIGH
Internal ResourceId collision may affect unrelated collections
Record summary
CVE-2026-25612 has a selected CVSS score of 7.1 (high).
Description
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB ServerBrowse MongoDB Inc / MongoDB ServerDefault status: unaffected | CVE List | 8.2 to < 8.2.4 | affected |
| 8.0 to < 8.0.18 | affected | ||
| 7.0 to < 7.0.29 | affected |
References
3jira.mongodb.org
https://jira.mongodb.org/browse/SERVER-115296 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-25612