CVE-2025-12657: MongoDB
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
Affected products
- MongoDB MongoDB: from 6.0.0, before 7.0.22 (fixed in 7.0.22); from 8.0.0, before 8.0.10 (fixed in 8.0.10)
Published 2025-11-03. Last modified 2026-06-17.