---
id: CVE-2025-11979
title: An authorized user may crash the MongoDB server by causing buffer over-read
summary: >-
  An authorized user may crash the MongoDB server by causing buffer over-read.
  This can be done by issuing a DDL operation while queries are being issued,
  under some conditions. This issue affects MongoDB Server v7.0 versions prior
  to 7.0.…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-416
vendor: mongodb
product: mongodb
affected:
  - 'mongodb >= 7.0.0, < 7.0.25'
  - 'mongodb >= 8.0.0, < 8.0.15'
patched:
  - mongodb 8.0.15
published: '2025-10-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11979'
references:
  - url: 'https://jira.mongodb.org/browse/SERVER-105873'
    label: cna@mongodb.com
tags:
  - nvd
epss: 0.00269
epssPercentile: 0.17511
ingestedAt: '2026-10-08T22:11:53.819Z'
---

## Overview

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to 8.0.15, and MongoDB Server version 8.2.0.

## Affected

- `mongodb >= 7.0.0, < 7.0.25`
- `mongodb >= 8.0.0, < 8.0.15`

## Remediation

Upgrade past the affected range:

- `mongodb 8.0.15`
