Use After Free Vulnerability in MongoDB Server from MongoDB Inc.
CVE-2025-6706

5MEDIUM

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
26 June 2025

What is CVE-2025-6706?

An authenticated user may exploit a use after free vulnerability in MongoDB Server, potentially leading to server crashes or erratic behavior. This issue arises when certain rare combinations of aggregation pipeline expressions are used during aggregation framework operations. Despite the user's lack of authorization to shut down the server, the vulnerability allows for unexpected outcomes. This impacts MongoDB Server versions prior to 6.0.21, 7.0.17, and 8.0.4 when the SBE engine is enabled.

Affected Version(s)

MongoDB Server 6.0 < 6.0.21

MongoDB Server 7.0 < 7.0.17

MongoDB Server 8.0 < 8.0.4

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6706 : Use After Free Vulnerability in MongoDB Server from MongoDB Inc.