Security Advisory

CVE-2025-12657

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-11-03 21:03:25
Last updated 2025-11-03 21:26:22
Assigner mongodb
State PUBLISHED

Description

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.