CVE-2026-25611: Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server
Published Feb 10, 2026
·Updated
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.
Affected Software
1 affected component
MongoDB MongoDB Server
Event History
Feb 10, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Sep 6, 58098
Event
via FIRST·06:09 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-25611?
CVE-2026-25611 is considered a high severity vulnerability due to its potential to cause a denial of service by exhausting memory.
2
How do I fix CVE-2026-25611?
To remediate CVE-2026-25611, update to the latest patched version of MongoDB server as recommended by MongoDB.
3
What type of attack is associated with CVE-2026-25611?
CVE-2026-25611 is associated with pre-authentication memory exhaustion attacks targeting MongoDB servers.
4
Who is affected by CVE-2026-25611?
CVE-2026-25611 affects all versions of MongoDB Server that are vulnerable to specifically crafted unauthenticated messages.
5
What are the symptoms of CVE-2026-25611 exploitation?
Exploitation of CVE-2026-25611 can result in the MongoDB server crashing due to memory exhaustion.