A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-103582 |
|
History
Thu, 11 Dec 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* cpe:2.3:a:mongodb:mongodb:8.2.0:alpha0:*:*:-:*:*:* cpe:2.3:a:mongodb:mongodb:8.2.0:alpha1:*:*:-:*:*:* cpe:2.3:a:mongodb:mongodb:8.2.0:alpha2:*:*:-:*:*:* cpe:2.3:a:mongodb:mongodb:8.2.0:alpha:*:*:-:*:*:* |
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb |
|
| Vendors & Products |
Mongodb
Mongodb mongodb |
Tue, 25 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14 | |
| Title | MongoDB Server may allow queries to be terminated by unauthorized users | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2025-11-25T05:16:24.472Z
Updated: 2025-11-25T16:41:18.237Z
Reserved: 2025-11-25T05:08:50.848Z
Link: CVE-2025-13643
Updated: 2025-11-25T16:41:15.602Z
Status : Analyzed
Published: 2025-11-25T06:15:45.580
Modified: 2025-12-11T23:20:36.673
Link: CVE-2025-13643
No data.