CVE-2025-12119: MongoDB C Driver

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Affected products

  • MongoDB C Driver: from 1.9.0, before 1.30.6 (fixed in 1.30.6); from 2.0.0, before 2.1.2 (fixed in 2.1.2)
  • MongoDB PHP Driver: before 1.21.2 (fixed in 1.21.2)

Published 2025-11-18. Last modified 2026-10-07.