An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.
{
"cna_assigner": "mongodb",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10059.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "6.0"
},
{
"fixed": "6.0.24"
},
{
"introduced": "7.0"
},
{
"fixed": "7.0.18"
},
{
"introduced": "8.0"
},
{
"fixed": "8.0.6"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-732"
]
}{
"cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.24"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.18"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.6"
}
],
"source": "CPE_RANGE"
}"2026-07-22T03:36:03Z"
[
{
"target": {
"file": "src/mongo/db/repl/oplog_applier_impl.cpp"
},
"id": "CVE-2025-10059-30d30407",
"digest": {
"line_hashes": [
"259138757267497787322732660740307019147",
"132000857137170557431027225526182190543",
"219296449103344026824906174079893054414",
"5720932185945374029998360576327319478"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/mongodb/mongo/commit/c5423a4f25b3056ee2380ddc4e5e5fc3f5a6afc2"
},
{
"target": {
"function": "OplogApplierImpl::_run",
"file": "src/mongo/db/repl/oplog_applier_impl.cpp"
},
"id": "CVE-2025-10059-651640f6",
"digest": {
"function_hash": "254642164138027264659524708034929552096",
"length": 2368.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/c5423a4f25b3056ee2380ddc4e5e5fc3f5a6afc2"
},
{
"target": {
"function": "CollectionRoutingInfoTargeter::_targetQuery",
"file": "src/mongo/s/collection_routing_info_targeter.cpp"
},
"id": "CVE-2025-10059-b35324af",
"digest": {
"function_hash": "270348088771156963022993784675396103736",
"length": 827.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/01446737d14e8e41feba33b2a5b7538c4b0fdc89"
},
{
"target": {
"file": "src/mongo/s/collection_routing_info_targeter.cpp"
},
"id": "CVE-2025-10059-ff8803f2",
"digest": {
"line_hashes": [
"200589201934254357811463676773712275958",
"63605353816517337771785508199529866736",
"80109071181097913300146229557150592459",
"223503303510403772449454539366973737259",
"206307475781743155230171432035110126298",
"209462201861701036355955731340079539923",
"104764857285727897851241798430944180616",
"90235110007444317084516985049945193792"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/mongodb/mongo/commit/01446737d14e8e41feba33b2a5b7538c4b0fdc89"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10059.json"