CVE-2025-12119
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-12-08
Assigner: MongoDB, Inc.
Description
Description
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mongodb | c_driver | From 1.9.0 (inc) to 1.30.6 (exc) |
| mongodb | c_driver | From 2.0.0 (inc) to 2.1.2 (exc) |
| mongodb | php_driver | to 1.21.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-825 | The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid. |