CVE-2025-13644: MongoDB may be susceptible to Invariant Failure due to batched delete

Published Nov 25, 2025
·
Updated

MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to 7.0.26, MongoDB Server v8.0 versions prior to 8.0.13, and MongoDB Server v8.1 versions prior to 8.1.2

Affected Software

10 affected components
MongoDB MongoDB Server<7.0.26
MongoDB MongoDB Server<8.0.13
MongoDB MongoDB Server<8.1.2
MongoDB MongoDB>=7.0.0<7.0.26
MongoDB MongoDB>=8.0.0<8.0.13
MongoDB MongoDB>=8.1.0<8.1.2
MongoDB MongoDB=8.2.0-alpha
MongoDB MongoDB=8.2.0-alpha0
MongoDB MongoDB=8.2.0-alpha1
MongoDB MongoDB=8.2.0-alpha2

Event History

Nov 25, 2025
CVE Published
via MITRE·05:23 AM
Data Sourced
via MITRE·05:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-13644?

The severity of CVE-2025-13644 is classified as high due to its potential to cause invariant failures during batched delete operations.

2

How do I fix CVE-2025-13644?

To fix CVE-2025-13644, update MongoDB Server to version 7.0.26 or later, or 8.0.13 or later.

3

What systems are affected by CVE-2025-13644?

CVE-2025-13644 affects MongoDB Server versions prior to 7.0.26, 8.0.13, and 8.1.2.

4

What are the potential risks of CVE-2025-13644?

The potential risks of CVE-2025-13644 include data loss and application crashes during batched delete operations.

5

Is there a workaround for CVE-2025-13644?

Currently, there are no recommended workarounds for CVE-2025-13644 aside from upgrading to the patched versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203