CVE-2026-25612: MongoDB Inc MongoDB Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.
Affected products
- MongoDB Inc MongoDB Server: from 8.2, before 8.2.4 (fixed in 8.2.4); from 8.0, before 8.0.18 (fixed in 8.0.18); from 7.0, before 7.0.29 (fixed in 7.0.29)
Published 2026-02-10. Last modified 2026-06-17.