Unrated severityNVD Advisory· Published Nov 25, 2025· Updated Nov 25, 2025
Time-series operations may cause internal BSON size limit to be exceed
CVE-2025-13507
Description
Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to 8.2.1.
Affected products
2- Range: >=7.0.0 <7.0.26, >=8.0.0 <8.0.16, >=8.2.0 <8.2.1
- MongoDB Inc./MongoDB Serverv5Range: 7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.