CVE-2025-11979

    Dashboard / Vulnerabilities / CVE-2025-11979

    CVE-2025-11979

    Published: 20 Oct 2025Last Modified: 10 Oct 2026

    Summary: Use-after-free in the MongoDB server query planner may lead to crash or undefined behavior

    Details: An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to 8.0.15, and MongoDB Server version 8.2.0.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 37d84072b5c5b9fd723db5fa133fb202ad2317f1

    Affected versions

    r8.0.14-rc1
    r8.0.14
    r8.0.14-rc0
    r8.0.13-rc2
    r8.0.13
    r8.0.13-rc1
    r8.0.13-rc0
    r8.0.12-rc0
    r8.0.12
    r8.0.10-rc0
    r8.0.10
    r8.0.6
    r8.0.5-rc2
    r8.0.5
    r8.0.5-rc1
    r8.0.5-rc0
    r8.0.4-rc0
    r8.0.4
    r8.0.3
    r8.0.2
    r8.0.1-rc0
    r8.0.1
    r8.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2025-11979 | CVE-DB