CVE-2025-12657

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-101230 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

12 Dec 2025, 17:22

Type Values Removed Values Added
First Time Mongodb
Mongodb mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
References () https://jira.mongodb.org/browse/SERVER-101230 - () https://jira.mongodb.org/browse/SERVER-101230 - Vendor Advisory

03 Nov 2025, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-03 21:18

Updated : 2025-12-12 17:22


NVD link : CVE-2025-12657

Mitre link : CVE-2025-12657

CVE.ORG link : CVE-2025-12657


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions