Aller au contenu

Fiche vulnérabilité

CVE-2025-10060 : faille élevée mongodb mongodb (CVSS 7.5)

Description

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
5 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • mongodb mongodb

Références

Rechercher une autre vulnérabilité dans la base CVE