MongoDB Server Improper Argument Validation in Explain Command Leading to Router Crash

Vulnerability

A vulnerability exists in MongoDB Server in versions 5.0 prior to 5.0.31, 6.0 prior to 6.0.20, 7.0 prior to 7.0.16, and 8.0 prior to 8.0.4. The issue arises from the explain command's failure to properly validate certain arguments before use, which can result in crashes on router servers.

Impact

Exploitation of this vulnerability can cause a crash in the router servers, disrupting normal operations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.9
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.