CVE-2025-10061 Affecting mongodb package, versions *


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.31% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1804-MONGODB-12554266
  • published26 Feb 2026
  • disclosed5 Sept 2025

Introduced: 5 Sep 2025

CVE-2025-10061  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:18.04 mongodb.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mongodb package and not the mongodb package as distributed by Ubuntu. See How to fix? for Ubuntu:18.04 relevant fixed versions and status.

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability could lead to denial of service if triggered repeatedly. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22, MongoDB Server v8.0 versions prior to 8.0.12 and MongoDB Server v8.1 versions prior to 8.1.2