CVE-2025-10060

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-10060
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-10060.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-10060
Aliases
Downstream
Published
2025-09-05T21:15:34.980Z
Modified
2025-11-16T12:22:55.387329Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12

References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events

Affected versions

r6.*

r6.0.0
r6.0.1
r6.0.1-rc0
r6.0.10
r6.0.10-rc0
r6.0.11
r6.0.11-rc0
r6.0.12
r6.0.12-rc0
r6.0.12-rc1
r6.0.13
r6.0.13-rc0
r6.0.14
r6.0.14-rc0
r6.0.14-rc1
r6.0.15
r6.0.15-rc0
r6.0.16
r6.0.16-rc0
r6.0.17
r6.0.17-rc0
r6.0.18
r6.0.18-rc0
r6.0.19
r6.0.2
r6.0.2-rc0
r6.0.2-rc1
r6.0.20
r6.0.20-rc0
r6.0.20-rc1
r6.0.20-rc2
r6.0.20-rc3
r6.0.21
r6.0.24
r6.0.24-alpha0
r6.0.24-rc0
r6.0.3
r6.0.3-rc0
r6.0.3-rc1
r6.0.3-rc2
r6.0.4
r6.0.4-rc0
r6.0.4-rc1
r6.0.5
r6.0.5-rc0
r6.0.5-rc1
r6.0.6
r6.0.6-rc0
r6.0.6-rc1
r6.0.7
r6.0.7-rc0
r6.0.8
r6.0.8-rc0
r6.0.9
r6.0.9-rc0
r6.0.9-rc1

Database specific

vanir_signatures

[
    {
        "signature_type": "Line",
        "source": "https://github.com/mongodb/mongo/commit/4fd11df29e03a4b50a4495c3fdc6c16c51858895",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-10060-1dccff31",
        "digest": {
            "line_hashes": [
                "292158961675648430931830492008352527319",
                "22452996665156713278886266656821683156",
                "240193183779930215422242480672117026118",
                "115098850818398635184085706036299404821"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "src/mongo/db/s/txn_two_phase_commit_cmds.cpp"
        }
    }
]