CVE-2025-10060
MEDIUMDescription
MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12
Is your site exposed to CVE-2025-10060?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mongodb | mongodb |
| mongodb | mongodb |
| mongodb | mongodb |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-10060? +
How severe is CVE-2025-10060? +
What products are affected by CVE-2025-10060? +
How do I check if I'm vulnerable to CVE-2025-10060? +
Related Vulnerabilities
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from …
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be …
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided …
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial …
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that …