Vulnerability Description
The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 6.0.0, < 7.0.22 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-101230Vendor Advisory
FAQ
What is CVE-2025-12657?
CVE-2025-12657 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violat...
How severe is CVE-2025-12657?
CVE-2025-12657 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12657?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.