CVE-2025-12657

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-12657
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-12657.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-12657
Aliases
Downstream
Published
2025-11-03T21:18:50.400Z
Modified
2025-12-14T03:56:02.905940Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events

Database specific

vanir_signatures

[
    {
        "digest": {
            "function_hash": "170810567694619582218325827979320844819",
            "length": 222.0
        },
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query_test.cpp",
            "function": "TEST"
        },
        "id": "CVE-2025-12657-09cc0615",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "13236081645074493115127001406131911299",
                "32815437550975849390738133222164712455",
                "97250326467089322403696436759510875041",
                "130220526898473437428672593103114463037"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/get_executor.cpp"
        },
        "id": "CVE-2025-12657-28057e63",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "function_hash": "91660256789222474456476205099263621914",
            "length": 392.0
        },
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/query_planner_tree_test.cpp",
            "function": "TEST_F"
        },
        "id": "CVE-2025-12657-35dd40fb",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "259041850611534104466084886859312154654",
                "209571827967119472844100407222830729771",
                "221652195236482708432158039780313247440"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query.h"
        },
        "id": "CVE-2025-12657-4d96a211",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "function_hash": "179129717886469733075672751986633638480",
            "length": 121.0
        },
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query_test.cpp",
            "function": "TEST"
        },
        "id": "CVE-2025-12657-b4300cd3",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "55836396164299393863275218643947047121",
                "247898015159499049520840962143521581548",
                "23538965146590376039815961727495063309",
                "73893154509656724043861091875594038976"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query_encoder_test.cpp"
        },
        "id": "CVE-2025-12657-c4902ad9",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "80902743015685727946894915990527748965",
                "176949779465539464536476382397679852955",
                "138011484810510969231374758577969819287",
                "213412792009456961805509708886495972031",
                "108030136181449000469460296639111922283",
                "259216495627230221219155342714306677591",
                "248422617507567503859301171305254340460",
                "245172356663580774147851102062929329842",
                "7994405613649427159682553495468608834",
                "305257036493543719456646007101986473421",
                "208303643772143893856671318066682687209",
                "199288333105912257288505536857893054571",
                "130816849182030429263138698125736179179",
                "3803095995514920701987929798503187434",
                "331120441307678997525871227890531343653",
                "4014394743506684706307958354607111043",
                "145785154675042814859234771874744716077",
                "300795417569439173402529912154615822191",
                "112765197846815209255450283462700714039",
                "285473019838526984620851944074290052422"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query.cpp"
        },
        "id": "CVE-2025-12657-e110b1d7",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "319155624397254202599116224418532377270",
                "320519262511008027629451689690475781923",
                "208462697800841384490668256992285694018",
                "213346500170575268019869843214449743933",
                "247019561929076384094690448831332001219",
                "91764808502864669515496362977122693840",
                "258830790253090992989549304973920386937",
                "51852030045595014727650341916501865161",
                "140711571707803073313743064961857373733",
                "249806296299264674804490985719791734340",
                "204374830227116296807761629752258449460"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/canonical_query_test.cpp"
        },
        "id": "CVE-2025-12657-eb949776",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "250624715087004535328972305640756178805",
                "148536438517875864651429272475526442940",
                "165014192351556472067212166349818389903",
                "49068151080804240088294744416265804817",
                "287242365717231291471612982454676213701",
                "323584313059038749367409677271617447863",
                "86121875653440403020767995825324230918",
                "86345351477897519473606718549341170251",
                "291880075665522310213812374355336024030",
                "9791660833690490751516611827213350840",
                "303693624070357428057007922409213264272"
            ]
        },
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/query_planner_tree_test.cpp"
        },
        "id": "CVE-2025-12657-fa8a5c8b",
        "source": "https://github.com/mongodb/mongo/commit/dacdbc3df2fbe579b03336a2f01fc9aedf406a41"
    }
]