Unrated severityNVD Advisory· Published Nov 25, 2025· Updated Nov 25, 2025
MongoDB Server may allow queries to be terminated by unauthorized users
CVE-2025-13643
Description
A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14
Affected products
2- Range: >=7.0, <7.0.26; >=8.0, <8.0.14
- MongoDB Inc./MongoDB Serverv5Range: 8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.