#VU112101 Input validation error in MongoDB - CVE-2025-6709
Published: July 2, 2025
MongoDB
MongoDB, Inc.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of JSON input when using OIDC authentication. A remote non-authenticated attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.
Note, this vulnerability can be exploited by a non-authenticated attacker only against versions 7.x and 8.x. In 6.x branch authentication is required to exploit the vulnerability.