An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
{
"cna_assigner": "mongodb",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.0"
},
{
"fixed": "8.0.13"
},
{
"introduced": "7.0"
},
{
"fixed": "7.0.29"
}
],
"source": "AFFECTED_FIELD"
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25610.json",
"cwe_ids": [
"CWE-617"
]
}"2026-07-22T03:08:46Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25610.json"
[
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/service_entry_point_common.cpp"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"11272611040114298527385613556453291829",
"175117650864466198429070599697755025763",
"259372737161260841017051100781998432651",
"190191220307360414594805946771026217001",
"29054105381567763046288516247318577171",
"80859590129831648960865656848228415255",
"259393610319526121774434945054847506142"
]
},
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/b409fb494004bf0f7284059b806b3b751a2ec5d9",
"id": "CVE-2026-25610-b3f79aa4"
},
{
"signature_type": "Function",
"target": {
"file": "src/mongo/db/service_entry_point_common.cpp",
"function": "ExecCommandDatabase::_initiateCommand"
},
"deprecated": false,
"digest": {
"length": 9728.0,
"function_hash": "59615453827642453525115701432201606392"
},
"signature_version": "v1",
"source": "https://github.com/mongodb/mongo/commit/b409fb494004bf0f7284059b806b3b751a2ec5d9",
"id": "CVE-2026-25610-b50a3bee"
}
]