CVE-2025-3083

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 862

Summary

CVE-2025-3083 is a vulnerability in MongoDB's mongos component, which can be exploited by sending specifically crafted MongoDB wire protocol messages. This issue causes mongos to crash during command validation, and it can occur even without an authenticated connection. Versions of MongoDB v5.0 prior to 5.0.31, v6.0 prior to 6.0.20, and v7.0 prior to 7.0.16 are affected by this vulnerability. Successful exploitation could potentially lead to denial-of-service conditions or other potential security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share