CVE-2026-25612CWE-412

Internal ResourceId collision may affect unrelated collections

High · published February 10, 2026

CVSS v4.0
7.1
EPSS
0%
Percentile
9.7
In the wild
Unconfirmed
What it is

The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00199 · 9.7th percentile
Weakness
CWE-412 · Unrestricted Externally Accessible Lock
Published
2026-02-10T18:05Z
EPSS history
Timeline
  • 10 FEB 18:05Z
    Internal ResourceId collision may affect unrelated collections
    cvelistv5