VYPR
Unrated severityNVD Advisory· Published Nov 25, 2025· Updated Nov 25, 2025

MongoDB Server may allow queries to be terminated by unauthorized users

CVE-2025-13643

Description

A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14

Affected products

2
  • Range: >=7.0, <7.0.26; >=8.0, <8.0.14
  • MongoDB Inc./MongoDB Serverv5
    Range: 8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.