CVE-2025-12657

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-101230 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2025-11-03 21:18

Updated : 2025-12-12 17:22


NVD link : CVE-2025-12657

Mitre link : CVE-2025-12657

CVE.ORG link : CVE-2025-12657


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions