CVE-2025-6712

Source
https://cve.org/CVERecord?id=CVE-2025-6712
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6712.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6712
Aliases
Downstream
Published
2025-07-07T14:44:38.183Z
Modified
2026-07-22T04:02:48.436726Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
MongoDB Server may be susceptible to DoS due to Accumulated Memory Allocation
Details

MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal operations. In scenarios where certain internal processes persist longer than anticipated, memory consumption can increase, potentially impacting server stability and availability. This issue affects MongoDB Server v8.0 versions prior to 8.0.10

Database specific
{
    "cna_assigner": "mongodb",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6712.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0"
                },
                {
                    "fixed": "8.0.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-400"
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
{
    "cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.10"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

r8.*
r8.0.0
r8.0.1
r8.0.1-rc0
r8.0.2
r8.0.3
r8.0.4
r8.0.4-rc0
r8.0.5
r8.0.5-rc0
r8.0.5-rc1
r8.0.5-rc2
r8.0.6

Database specific

vanir_signatures_modified
"2026-07-22T04:02:48Z"
vanir_signatures
[
    {
        "target": {
            "file": "src/mongo/transport/asio/asio_session_impl.cpp"
        },
        "id": "CVE-2025-6712-506fa5cb",
        "digest": {
            "line_hashes": [
                "282765062060540820013904249999369091735",
                "300291622994495336463358897248157878965",
                "171295154459370418954909748630098851460",
                "264717989889958699510278395341009123178",
                "286921937843054147385921250452426071137",
                "212177683335443537294930353787718564470",
                "154072217225560505992627186916787245632",
                "339038656703438971026792802796071385997"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/mongodb/mongo/commit/a25a91f17ac7d38e530defb84840cef26964f0bd"
    },
    {
        "target": {
            "function": "CommonAsioSession::isLoadBalancerPeer",
            "file": "src/mongo/transport/asio/asio_session_impl.cpp"
        },
        "id": "CVE-2025-6712-aa314a9d",
        "digest": {
            "function_hash": "156090998067393006199077392588973597889",
            "length": 88.0
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/mongodb/mongo/commit/a25a91f17ac7d38e530defb84840cef26964f0bd"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6712.json"