An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.
History

Fri, 05 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 20:45:00 +0000

Type Values Removed Values Added
Description An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.
Title MongoDB Server router will crash when incorrect lsid is set on a sharded query
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-09-05T20:44:22.665Z

Reserved: 2025-09-05T20:10:54.977Z

Link: CVE-2025-10059

cve-icon Vulnrichment

Updated: 2025-09-05T20:43:09.491Z

cve-icon NVD

Status : Received

Published: 2025-09-05T21:15:34.773

Modified: 2025-09-05T21:15:34.773

Link: CVE-2025-10059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.