CVE-2025-12657

Publication date

2025-11-03 21:03:25

Family

mongodb

State

PUBLISHED

Description

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.