Unique Index Violation in MongoDB Server by MongoDB
CVE-2025-10060

6.5MEDIUM

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
5 September 2025

What is CVE-2025-10060?

MongoDB Server is susceptible to a vulnerability that may allow upsert operations, when retried within a transaction, to bypass unique index constraints. This issue can lead to invariant failures, resulting in server crashes during commit due to improper WriteUnitOfWork state management. It affects multiple versions of MongoDB Server, necessitating immediate attention to ensure the integrity and reliability of database operations. Users are advised to review product versions and apply the necessary updates.

Affected Version(s)

MongoDB Server 6.0 < 6.0.25

MongoDB Server 7.0 < 7.0.22

MongoDB Server 8.0 < 8.0.12

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10060 : Unique Index Violation in MongoDB Server by MongoDB