CVE-2025-10059 Details
Description
An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.
A vulnerability exists in MongoDB Server in the sharding component, specifically in versions 6.0 prior to 6.0.x, 7.0 prior to 7.0.18, and 8.0 prior to 8.0.6. The issue arises from an improper handling of the logical session identifier (lsid) field in sharded queries, which can lead to a crash in MongoDB routers. This problem occurs when a generic argument is introduced inappropriately, causing the server to crash instead of logging the incident as a programmer error.
Users can upgrade to MongoDB Server versions 8.0.6, 7.0.18, or 6.0.24 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jira.mongodb.org/browse/SERVER-100901 | [email protected] | Issue TrackingVendor Advisory |
| https://jira.mongodb.org/browse/SERVER-100909 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mongodb mongodb | >= 6.0.0, < 6.0.24 >= 7.0.0, < 7.0.18 >= 8.0.0, < 8.0.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2025 | Initial Analysis | [email protected] |
| Sep 5, 2025 | New CVE Received | [email protected] |