CVE-2025-13507

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-108565 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

05 Dec 2025, 20:23

Type Values Removed Values Added
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
First Time Mongodb
Mongodb mongodb
References () https://jira.mongodb.org/browse/SERVER-108565 - () https://jira.mongodb.org/browse/SERVER-108565 - Vendor Advisory

25 Nov 2025, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 05:16

Updated : 2025-12-05 20:23


NVD link : CVE-2025-13507

Mitre link : CVE-2025-13507

CVE.ORG link : CVE-2025-13507


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-1284

Improper Validation of Specified Quantity in Input