CVE-2025-12119: Bulk write with options may read invalid memory
Published Nov 18, 2025
·Updated
A mongocbulkoperationt may read invalid memory if large options are passed.
Affected Software
4 affected componentsFixes available
composer/mongodb/mongodb-extension<1.21.2
1.21.2
MongoDB C Driver Mongodb>=1.9.0<1.30.6
MongoDB C Driver Mongodb>=2.0.0<2.1.2
MongoDB Php Driver Mongodb<1.21.2
Event History
Nov 18, 2025
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
Affected Software
Nov 19, 2025
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12119?
CVE-2025-12119 is classified as a high severity vulnerability due to the potential for memory corruption.
2
How do I fix CVE-2025-12119?
To fix CVE-2025-12119, upgrade the mongodb/mongodb-extension to version 1.21.2 or later.
3
What impact does CVE-2025-12119 have on systems?
CVE-2025-12119 can lead to undefined behavior and application crashes due to reading invalid memory.
4
Which software versions are affected by CVE-2025-12119?
Versions of mongodb/mongodb-extension prior to 1.21.2 are affected by CVE-2025-12119.
5
Is there a workaround for CVE-2025-12119?
There are no known workarounds for CVE-2025-12119; upgrading is the recommended action.