CVE-2018-25004: MongoDB

Medium severity, CVSS 4.9. EPSS: 1% chance of exploitation in the next 30 days.

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

Affected products

  • MongoDB MongoDB: from 3.6.0, before 3.6.11 (fixed in 3.6.11); from 4.0.0, before 4.0.6 (fixed in 4.0.6)

Published 2021-03-01. Last modified 2026-06-17.