CVE-2025-11695

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5
References
Link Resource
https://jira.mongodb.org/browse/RUST-2264 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:rust_driver:*:*:*:*:*:mongodb:*:*

History

04 Dec 2025, 21:36

Type Values Removed Values Added
First Time Mongodb rust Driver
Mongodb
References () https://jira.mongodb.org/browse/RUST-2264 - () https://jira.mongodb.org/browse/RUST-2264 - Vendor Advisory
CPE cpe:2.3:a:mongodb:rust_driver:*:*:*:*:*:mongodb:*:*

13 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-13 17:15

Updated : 2025-12-04 21:36


NVD link : CVE-2025-11695

Mitre link : CVE-2025-11695

CVE.ORG link : CVE-2025-11695


JSON object : View

Products Affected

mongodb

  • rust_driver
CWE
CWE-295

Improper Certificate Validation