CVE-2025-6714
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20 and MongoDB Server v8.0 prior to 8.0.9 Required Configuration: This affects MongoDB sharded clusters when configured with load balancer support for mongos using HAProxy on specified ports.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.31%
- CWE
- CWE-834, CWE-400
- Published
- 2025-07-07
- Last modified
- 2026-03-12
Affected products
- MongoDB Inc MongoDB Server
- MongoDB Inc MongoDB Server
- MongoDB Inc MongoDB Server
Weakness type
Related vulnerabilities
- CVE-2026-16497 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause...
- CVE-2026-84311 — pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- CVE-2026-84310 — pypdf: Possible long runtimes/large memory usage when retrieving outlines
- CVE-2026-77357 — Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the server
- CVE-2026-71852 — pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- CVE-2026-59644 — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
- CVE-2026-64641 — Next.js: Denial of Service in App Router using Server Actions
- CVE-2026-50171 — Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)