Use After Free Vulnerability in MongoDB Server from MongoDB Inc.
CVE-2025-6706
5MEDIUM
What is CVE-2025-6706?
An authenticated user may exploit a use after free vulnerability in MongoDB Server, potentially leading to server crashes or erratic behavior. This issue arises when certain rare combinations of aggregation pipeline expressions are used during aggregation framework operations. Despite the user's lack of authorization to shut down the server, the vulnerability allows for unexpected outcomes. This impacts MongoDB Server versions prior to 6.0.21, 7.0.17, and 8.0.4 when the SBE engine is enabled.
Affected Version(s)
MongoDB Server 6.0 < 6.0.21
MongoDB Server 7.0 < 7.0.17
MongoDB Server 8.0 < 8.0.4