{"id":"CVE-2025-13643","summary":"MongoDB Server may allow queries to be terminated by unauthorized users","details":"A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB Server v8.0 versions prior to 8.0.14","aliases":["BIT-mongodb-2025-13643"],"modified":"2026-08-12T14:52:26.519764Z","published":"2025-11-25T05:16:24.472Z","database_specific":{"cna_assigner":"mongodb","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13643.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"8.0"},{"fixed":"8.0.14"},{"introduced":"7.0"},{"fixed":"7.0.26"}]}]},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/SERVER-103582"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13643.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13643"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo","events":[{"introduced":"37d84072b5c5b9fd723db5fa133fb202ad2317f1"},{"fixed":"cfe96f2560c2000d837880f3e49086bed560abec"},{"introduced":"b41cda4fe697dce6fd9b83b3805362ccc02fbeb3"},{"fixed":"667c242e00609bae2ddb7fe30c0ed9cca3320bdb"},{"introduced":"246b4fceaab08de8de2aa07c28ab06a06a8a2c61"},{"last_affected":"e1a5281f585ce2cf7f3d241835002c82d77ead48"}],"database_specific":{"extracted_events":[{"introduced":"7.0.0"},{"fixed":"7.0.26"},{"introduced":"8.0.0"},{"fixed":"8.0.14"},{"introduced":"8.2.0-alpha"},{"last_affected":"8.2.0-alpha"},{"introduced":"8.2.0-alpha0"},{"last_affected":"8.2.0-alpha0"},{"introduced":"8.2.0-alpha1"},{"last_affected":"8.2.0-alpha1"},{"introduced":"8.2.0-alpha2"},{"last_affected":"8.2.0-alpha2"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*","cpe:2.3:a:mongodb:mongodb:8.2.0:alpha:*:*:-:*:*:*","cpe:2.3:a:mongodb:mongodb:8.2.0:alpha0:*:*:-:*:*:*","cpe:2.3:a:mongodb:mongodb:8.2.0:alpha1:*:*:-:*:*:*","cpe:2.3:a:mongodb:mongodb:8.2.0:alpha2:*:*:-:*:*:*"]}}],"versions":["8.2.0-alpha","8.2.0-alpha0","8.2.0-alpha1","8.2.0-alpha2","r7.0.24-rc0","r7.0.24","r7.0.25-alpha0","r8.0.14-rc0","r8.0.13-rc2","r8.0.13","r8.0.13-rc1","r8.0.13-rc0","r7.0.23-rc1","r7.0.23","r7.0.23-rc0","r8.2.0-alpha2","r8.2.0-alpha1","r8.2.0-alpha0","r7.0.22-rc0","r7.0.22","r8.0.12-rc0","r8.0.12","r8.0.10-rc0","r8.0.10","r7.0.21-rc0","r7.0.21","r7.0.21-alpha0","r7.0.18","r8.0.6","r8.2.0-alpha","r7.0.17","r8.0.5-rc2","r8.0.5","r8.0.5-rc1","r8.0.5-rc0","r7.0.16-rc1","r7.0.16-rc0","r7.0.16","r8.0.4-rc0","r8.0.4","r7.0.15","r8.0.3","r8.0.2","r7.0.15-rc1","r7.0.15-rc0","r8.0.1-rc0","r8.0.1","r8.0.0","r7.0.14-rc0","r7.0.14","r7.0.13-rc1","r7.0.13","r7.0.13-rc0","r7.0.12-rc1","r7.0.12","r7.0.12-rc0","r7.0.11-rc2","r7.0.11","r7.0.11-rc1","r7.0.11-rc0","r7.0.10-rc0","r7.0.10","r7.0.9-rc1","r7.0.9","r7.0.9-rc0","r7.0.8-rc0","r7.0.8","r7.0.7-rc2","r7.0.7","r7.0.7-rc1","r7.0.7-rc0","r7.0.6-rc0","r7.0.6","r7.0.5-rc0","r7.0.5","r7.0.4-rc0","r7.0.4","r7.0.3-rc1","r7.0.3","r7.0.3-rc0","r7.0.2-rc2","r7.0.2","r7.0.2-rc1","r7.0.2-rc0","r7.0.1-rc0","r7.0.1","r7.0.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T14:52:26Z","vanir_signatures":[{"source":"https://github.com/mongodb/mongo/commit/cfe96f2560c2000d837880f3e49086bed560abec","target":{"file":"src/mongo/util/net/ssl_manager_windows.cpp","function":"validatePeerCertificate"},"deprecated":false,"digest":{"length":5523,"function_hash":"169396510644917166107972285471505278925"},"id":"CVE-2025-13643-0d7700d5","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2025-13643-1ac5af1d","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/cfe96f2560c2000d837880f3e49086bed560abec","target":{"file":"src/mongo/util/net/ssl_manager_windows.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["255094620203238166973302767875286180987","311318788437859314187108745684874069447","13195629967762718487111799273423913192","145659902616350294817239749199959363992","221972074441494021565962355714822796262","48835208987546656192845547932509644477","87708939807646049295739831013123777386","10193593850898967193818537886210518552","331231889353555350497810337678926637920","152234860073312542299676805758359870241"]}},{"deprecated":false,"digest":{"line_hashes":["52207717764756858887103230689427858974","241284099896496899084843301553798842386","81015194422365157642401834775353309989","306832239360780013917147226125039650941"],"threshold":0.9},"id":"CVE-2025-13643-5d8a373e","signature_type":"Line","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/cfe96f2560c2000d837880f3e49086bed560abec","target":{"file":"src/mongo/util/net/ssl_manager_apple.cpp"}},{"deprecated":false,"digest":{"length":715,"function_hash":"60854262378866240810463600752329606435"},"id":"CVE-2025-13643-a2bd2a3d","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/cfe96f2560c2000d837880f3e49086bed560abec","target":{"file":"src/mongo/util/net/ssl_manager_apple.cpp","function":"CreateSecTrustPolicies"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13643.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}