CVE-2025-13644
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-25

Last updated on: 2025-12-11

Assigner: MongoDB, Inc.

Description
MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-25
Last Modified
2025-12-11
Generated
2026-05-07
AI Q&A
2025-11-25
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 7 associated CPEs
Vendor Product Version / Range
mongodb mongodb From 7.0.0 (inc) to 7.0.26 (exc)
mongodb mongodb From 8.0.0 (inc) to 8.0.13 (exc)
mongodb mongodb From 8.1.0 (inc) to 8.1.2 (exc)
mongodb mongodb 8.2.0
mongodb mongodb 8.2.0
mongodb mongodb 8.2.0
mongodb mongodb 8.2.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability occurs in MongoDB Server during batched delete operations. The server incorrectly assumes that multiple documents are present in a batch based only on the document size exceeding BSONObjMaxSize, which can lead to an invariant failure.


How can this vulnerability impact me? :

The vulnerability can cause an invariant failure in the MongoDB Server during batched delete operations, potentially leading to denial of service or server instability. This could disrupt database operations and availability.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade MongoDB Server to version 7.0.26 or later, 8.0.13 or later, or 8.1.2 or later, depending on your current version series.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart