CVE Vulnerabilities

CVE-2026-25611

Asymmetric Resource Consumption (Amplification)

Published: Feb 10, 2026 | Modified: Feb 10, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

NameVendorStart VersionEnd Version
MongodbUbuntuupstream*

Potential Mitigations

References