CVE-2025-6711

Source
https://cve.org/CVERecord?id=CVE-2025-6711
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-6711.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-6711
Aliases
Downstream
Published
2025-07-07T15:15:28.703Z
Modified
2026-03-09T23:57:42.038228Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v6.0 versions prior to 6.0.21.

References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
{
    "versions": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.0.21"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.18"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.0.5"
        }
    ]
}

Affected versions

r6.*
r6.0.0
r6.0.1
r6.0.1-rc0
r6.0.10
r6.0.10-rc0
r6.0.11
r6.0.11-rc0
r6.0.12
r6.0.12-rc0
r6.0.12-rc1
r6.0.13
r6.0.13-rc0
r6.0.14
r6.0.14-rc0
r6.0.14-rc1
r6.0.15
r6.0.15-rc0
r6.0.16
r6.0.16-rc0
r6.0.17
r6.0.17-rc0
r6.0.18
r6.0.18-rc0
r6.0.19
r6.0.2
r6.0.2-rc0
r6.0.2-rc1
r6.0.20
r6.0.20-rc0
r6.0.20-rc1
r6.0.20-rc2
r6.0.20-rc3
r6.0.3
r6.0.3-rc0
r6.0.3-rc1
r6.0.3-rc2
r6.0.4
r6.0.4-rc0
r6.0.4-rc1
r6.0.5
r6.0.5-rc0
r6.0.5-rc1
r6.0.6
r6.0.6-rc0
r6.0.6-rc1
r6.0.7
r6.0.7-rc0
r6.0.8
r6.0.8-rc0
r6.0.9
r6.0.9-rc0
r6.0.9-rc1
r7.*
r7.0.0
r7.0.1
r7.0.1-rc0
r7.0.10
r7.0.10-rc0
r7.0.11
r7.0.11-rc0
r7.0.11-rc1
r7.0.11-rc2
r7.0.12
r7.0.12-rc0
r7.0.12-rc1
r7.0.13
r7.0.13-rc0
r7.0.13-rc1
r7.0.14
r7.0.14-rc0
r7.0.15
r7.0.15-rc0
r7.0.15-rc1
r7.0.16
r7.0.16-rc0
r7.0.16-rc1
r7.0.17
r7.0.2
r7.0.2-rc0
r7.0.2-rc1
r7.0.2-rc2
r7.0.3
r7.0.3-rc0
r7.0.3-rc1
r7.0.4
r7.0.4-rc0
r7.0.5
r7.0.5-rc0
r7.0.6
r7.0.6-rc0
r7.0.7
r7.0.7-rc0
r7.0.7-rc1
r7.0.7-rc2
r7.0.8
r7.0.8-rc0
r7.0.9
r7.0.9-rc0
r7.0.9-rc1
r8.*
r8.0.0
r8.0.1
r8.0.1-rc0
r8.0.2
r8.0.3
r8.0.4
r8.0.4-rc0
r8.0.5-rc0
r8.0.5-rc1

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "target": {
            "function": "ClassicStageBuilder::build",
            "file": "src/mongo/db/query/classic_stage_builder.cpp"
        },
        "digest": {
            "length": 11998.0,
            "function_hash": "324731960150289540980834762556588772295"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-02da7f08",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "PlanEnumerator::getNext",
            "file": "src/mongo/db/query/plan_enumerator.cpp"
        },
        "digest": {
            "length": 355.0,
            "function_hash": "74721346382742554427103070829589351717"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-04aca510",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "QueryPlannerIXSelect::_compatible",
            "file": "src/mongo/db/query/planner_ixselect.cpp"
        },
        "digest": {
            "length": 5055.0,
            "function_hash": "6750677528220597691009422494444808667"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-0ca6dbf5",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/planner_ixselect.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "10066572042982452419190648275880004759",
                "198010942107892612119844421222233465981",
                "238555843601584275087869651267173119853",
                "218292219009861977983067820021497983774"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-10d73161",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/unittest/death_test.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "66747486518425923489000982985828416312",
                "66965966368288672247966435120034690757",
                "216452294733543330044469750897653841440",
                "321073959764106855778235126773976578717",
                "212982771766741900162197822039487310625",
                "278079999784330475196550456161237500448",
                "94858199688620481836041042337777616687",
                "148807512214169000249497408166764724234",
                "136451342793459111323744436382072994225",
                "330133628046486975141314419369345094322",
                "325658352348944307183031272830281185111",
                "311618813173629078580658457448270110667",
                "301936308844104445279166337006487839208"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Line",
        "id": "CVE-2025-6711-1b22917d",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/commands/getmore_cmd.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "323675016611822908901520286437579331970",
                "134018369373461896889428775379890327204",
                "110060140195004104665048901947222996114",
                "49252125840708939910580577962037129759"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-320a26f6",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/plan_executor_factory.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "74480530075972489207882079862334429764",
                "76410312924971237751169851963874629808",
                "79022626286008810693439777307702037688",
                "63471234647693922887625181921846898126",
                "213512571532026548196990037065560722984",
                "216953702257803626192425694834763335091",
                "184599858042867205163347561657227639026",
                "334283130975759149651470692416758486813",
                "143946319678917081822532102637446812885",
                "238540202553349890141274583720274765758"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-34accfc1",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/commands/run_aggregate.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "325934018512381950537697277337436246001",
                "182718589902973117584251429550925210539",
                "7436171749258214253947874812145720868",
                "116396899814353271616125903432356141976"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-3dfd0052",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/bson/json.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "55291228322113123472651093450521503599",
                "180018901921691706908659934931964657311",
                "26428813386726412500243738304337006991",
                "66872429548502555232343484422131280617",
                "27615411616634180615233341240025803872"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Line",
        "id": "CVE-2025-6711-437581b3",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "handleCursorCommand",
            "file": "src/mongo/db/commands/run_aggregate.cpp"
        },
        "digest": {
            "length": 3655.0,
            "function_hash": "315579720131735595828496019705066544473"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-450be5e7",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/classic_stage_builder.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "53195843026111884998938521343974374173",
                "230237911581286265848288504352558145943",
                "209305753029730154019924762943689408857",
                "188278831708682375185310562172448117050"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-46b55b85",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/query_stats/query_stats.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "117996222717711035934246435470014861681",
                "134503435815170199102225179521540750073",
                "186482670758146755212771325428210146174",
                "175448674506301054507302686564081847271"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-5db5e3f0",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/expression_index.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "239760245189374196199053087318019641219",
                "166658240041078105533858403956415681461",
                "184613860848971087935595557361706193125",
                "21627686114844893390008975237787558063",
                "270299295809016924007056676644411041761",
                "164457883294828323493140586031241570462",
                "184613860848971087935595557361706193125",
                "21627686114844893390008975237787558063"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-649dcc19",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "makeIntervalsFromIndexBounds",
            "file": "src/mongo/db/query/sbe_stage_builder_index_scan.cpp"
        },
        "digest": {
            "length": 1499.0,
            "function_hash": "330353328274016122203123709077513116764"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-73db0d9b",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/plan_enumerator.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "9363958036791989920855153754359125296",
                "212614258808394553218503732579496811630",
                "324828096798884775161546544166307853114",
                "311240997386380183087492118537665622982"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-7f149475",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/commands/distinct.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "205050424898769862710277687559331953608",
                "108188596002158574450440502237856818599",
                "21459500346659147619504989491625648974",
                "23316749593539662910705972082917395804"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-9e183a45",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "run",
            "file": "src/mongo/db/commands/find_cmd.cpp"
        },
        "digest": {
            "length": 8399.0,
            "function_hash": "271326683273544982550950067365164714652"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-a5fa4151",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "make",
            "file": "src/mongo/db/query/plan_executor_factory.cpp"
        },
        "digest": {
            "length": 552.0,
            "function_hash": "18683832206106765511076032648809337438"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-a791dd5f",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "CollectionRoutingInfoTargeter::_targetQuery",
            "file": "src/mongo/s/collection_routing_info_targeter.cpp"
        },
        "digest": {
            "length": 827.0,
            "function_hash": "270348088771156963022993784675396103736"
        },
        "source": "https://github.com/mongodb/mongo/commit/01446737d14e8e41feba33b2a5b7538c4b0fdc89",
        "signature_type": "Function",
        "id": "CVE-2025-6711-b35324af",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/bson/json.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "316812224940597349210802207153468412354",
                "182540187870046299377185840611309772662",
                "26235693254835517178998203862684720123",
                "288365987673642931808837033988182548224",
                "12634805768102346354597642259202202781",
                "124963060713168580629168936788391930536",
                "293631087943889812256072568006311929606",
                "129313858920652648405295319762570784376",
                "205723985492844250042200083227006731872",
                "295305126718174767852394771211441977557",
                "214372823518818284513240378260029913297",
                "154839776255203802542823475742103318348",
                "63966623324690558132458878876408542365",
                "227886298463909455701668011020739809800",
                "274719377545742581878851119981020161722",
                "118018990569479107859615394364893193514",
                "300711920207147043942293811610763238167",
                "53728239849209811192533802918800223350",
                "243132182210154584977178726137214177431",
                "39369041185148501037962423918294899723",
                "128474132530057300850619398133175026668",
                "8186317940670349698100805971036852288",
                "248484137817490873357539971574352476654",
                "262181123974261924674842333426546494632",
                "90278502623191581481154302716035029854"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Line",
        "id": "CVE-2025-6711-b49ba713",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "fromjson",
            "file": "src/mongo/bson/json.cpp"
        },
        "digest": {
            "length": 626.0,
            "function_hash": "222574750477560596096716589933537609235"
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Function",
        "id": "CVE-2025-6711-b5a853d3",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "ExpressionMapping::S2CellIdsToIntervals",
            "file": "src/mongo/db/query/expression_index.cpp"
        },
        "digest": {
            "length": 418.0,
            "function_hash": "127231367950262132446204453201931301605"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-ba6bb206",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "ExpressionMapping::S2CellIdsToIntervalsWithParents",
            "file": "src/mongo/db/query/expression_index.cpp"
        },
        "digest": {
            "length": 812.0,
            "function_hash": "198790066288247663210850446148914273963"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-c0854628",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "DeathTestBase::Subprocess::monitorChild",
            "file": "src/mongo/unittest/death_test.cpp"
        },
        "digest": {
            "length": 1948.0,
            "function_hash": "47283986914761325475926390744079264293"
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Function",
        "id": "CVE-2025-6711-ce280be5",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/commands/find_cmd.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "305366697272645678512491038926620382457",
                "267277981781185756058943621693643061891",
                "327333684406704850282880008980341516469",
                "90672606295781307607942416164877328061"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-d8fdb3ce",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "generateBatch",
            "file": "src/mongo/db/commands/getmore_cmd.cpp"
        },
        "digest": {
            "length": 1998.0,
            "function_hash": "7584353214389406896055162675308718886"
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Function",
        "id": "CVE-2025-6711-de645406",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/db/query/sbe_stage_builder_index_scan.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "207116781706962205856707717630023094228",
                "135169221765852504545383737733425835422",
                "51443341853513551633927610171554928141",
                "245965675408929541120275929136782993672",
                "250754446376793506390399135194343105764"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/f4184f18fe405b75258e85a8554481128fb46410",
        "signature_type": "Line",
        "id": "CVE-2025-6711-e46308c7",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "fromjson",
            "file": "src/mongo/bson/json.cpp"
        },
        "digest": {
            "length": 89.0,
            "function_hash": "336468060843055155798902538574741651238"
        },
        "source": "https://github.com/mongodb/mongo/commit/07391eabd130b66d493b22cf46cb258acd7f290f",
        "signature_type": "Function",
        "id": "CVE-2025-6711-f6d1e7e7",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "src/mongo/s/collection_routing_info_targeter.cpp"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "200589201934254357811463676773712275958",
                "63605353816517337771785508199529866736",
                "80109071181097913300146229557150592459",
                "223503303510403772449454539366973737259",
                "206307475781743155230171432035110126298",
                "209462201861701036355955731340079539923",
                "104764857285727897851241798430944180616",
                "90235110007444317084516985049945193792"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/01446737d14e8e41feba33b2a5b7538c4b0fdc89",
        "signature_type": "Line",
        "id": "CVE-2025-6711-ff8803f2",
        "deprecated": false
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-6711.json"