CVE-2025-3084
When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4
- Affected products
- Alt Linux, Mongodb Server, Mongodb, Red Os
- Mongodb
- < 5.0.31, 6.0.20, 7.0.16, 8.0.4
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.4% (31th percentile)
- Weakness
- CWE-703
- NVD status
- Analyzed
- Published
- 2025-04-01
CVE-2025-3084 at NVD
No indexed exploits for CVE-2025-3084 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-3084 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.