CVE-2025-10059 – MongoDB Server router will crash when incorrect lsid is set on a sharded query

The following table lists the changes that have been made to the
CVE-2025-10059 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 05, 2025

    Action Type Old Value New Value
    Added Description An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-732
    Added Reference https://jira.mongodb.org/browse/SERVER-100901
    Added Reference https://jira.mongodb.org/browse/SERVER-100909
Share the Post:

Related Posts