CVE intelligence
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
Mongodb · Published 2025-12-19 · CVSS 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NAVAttack VectorNetworkACAttack ComplexityLowATAttack RequirementsNonePRPrivileges RequiredNoneUIUser InteractionNoneVCVulnerable System ConfidentialityHighVIVulnerable System IntegrityNoneVAVulnerable System AvailabilityNoneSCSubsequent System ConfidentialityNoneSISubsequent System IntegrityNoneSASubsequent System AvailabilityNone high · KEV listed 2025-12-29 · Action due 2026-01-19
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AV
AC
AT
PR
UI
VC
VI
VA
SC
SI
SA
NIST record