Unique Index Violation in MongoDB Server by MongoDB
CVE-2025-10060
6.5MEDIUM
What is CVE-2025-10060?
MongoDB Server is susceptible to a vulnerability that may allow upsert operations, when retried within a transaction, to bypass unique index constraints. This issue can lead to invariant failures, resulting in server crashes during commit due to improper WriteUnitOfWork state management. It affects multiple versions of MongoDB Server, necessitating immediate attention to ensure the integrity and reliability of database operations. Users are advised to review product versions and apply the necessary updates.
Affected Version(s)
MongoDB Server 6.0 < 6.0.25
MongoDB Server 7.0 < 7.0.22
MongoDB Server 8.0 < 8.0.12