CVE-2025-6714
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-07

Last updated on: 2025-10-03

Assigner: MongoDB, Inc.

Description
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20 and MongoDB Server v8.0 prior to 8.0.9 Required Configuration: This affects MongoDB sharded clusters when configured with load balancer support for mongos using HAProxy on specified ports.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-07
Last Modified
2025-10-03
Generated
2026-05-07
AI Q&A
2025-07-07
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
mongodb mongodb From 8.1.0 (inc) to 8.1.2 (inc)
mongodb mongodb From 8.1.0 (inc) to 8.1.2 (inc)
mongodb mongodb From 8.1.0 (inc) to 8.1.2 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-834 The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in the mongos component of MongoDB Server when it is configured with load balancer support. Due to incorrect handling of incomplete data, mongos can become unresponsive to new connections. This affects specific versions of MongoDB Server prior to 6.0.23, 7.0.20, and 8.0.9 when used in sharded clusters with HAProxy load balancing on specified ports.


How can this vulnerability impact me? :

The vulnerability can cause the mongos component to become unresponsive to new connections, leading to potential denial of service in MongoDB sharded clusters configured with load balancer support. This can disrupt database availability and impact applications relying on MongoDB for data access.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart