CVE-2026-25612CWE-412
Internal ResourceId collision may affect unrelated collections
High · published February 10, 2026
What it is
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.
The record
Technical detail
- CVSS v4.0
- 7.1 · HIGH
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS
- 0.00199 · 9.7th percentile
- Weakness
- CWE-412 · Unrestricted Externally Accessible Lock
- Published
- 2026-02-10T18:05Z
EPSS history
Timeline