CVE-2025-10060 – MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation

The following table lists the changes that have been made to the
CVE-2025-10060 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 05, 2025

    Action Type Old Value New Value
    Added Description MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-672
    Added Reference https://jira.mongodb.org/browse/SERVER-95524
Share the Post:

Related Posts