CVE-2025-12119: MongoDB C Driver
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
Affected products
- MongoDB C Driver: from 1.9.0, before 1.30.6 (fixed in 1.30.6); from 2.0.0, before 2.1.2 (fixed in 2.1.2)
- MongoDB PHP Driver: before 1.21.2 (fixed in 1.21.2)
Published 2025-11-18. Last modified 2026-10-07.