Vulnerability Description
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVSS Score
6.8
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | C Driver | >= 1.9.0, < 1.30.6 |
| Mongodb | Php Driver | < 1.21.2 |
Related Weaknesses (CWE)
References
- https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6Release Notes
- https://github.com/mongodb/mongo-c-driver/releases/tag/2.1.2Release Notes
- https://github.com/mongodb/mongo-php-driver/releases/tag/1.21.2Release Notes
- https://lists.debian.org/debian-lts-announce/2026/01/msg00009.html
FAQ
What is CVE-2025-12119?
CVE-2025-12119 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A mongoc_bulk_operation_t may read invalid memory if large options are passed.
How severe is CVE-2025-12119?
CVE-2025-12119 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12119?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb C Driver, Mongodb Php Driver.