VYPR
Medium severity6.5NVD Advisory· Published Nov 25, 2025· Updated Jun 17, 2026

CVE-2025-13644

CVE-2025-13644

Description

MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • osv-coords
    Range: >= 7.0.0, < 7.0.26
  • MongoDB/MongoDB5 versions
    cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*+ 4 more
    • cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*range: >=7.0.0,<7.0.26
    • cpe:2.3:a:mongodb:mongodb:8.2.0:alpha:*:*:-:*:*:*
    • cpe:2.3:a:mongodb:mongodb:8.2.0:alpha0:*:*:-:*:*:*
    • cpe:2.3:a:mongodb:mongodb:8.2.0:alpha1:*:*:-:*:*:*
    • cpe:2.3:a:mongodb:mongodb:8.2.0:alpha2:*:*:-:*:*:*
  • MongoDB/Serverllm-fuzzy
    Range: <7.0.26, <8.0.13, <8.1.2
  • MongoDB Inc./MongoDB Serverv5
    Range: 8.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.