---
title: "CVE-2025-7259\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-7259?format=md
keywords: index, follow
---

# CVE-2025-7259

Publication date 7 July 2025

Last updated 18 February 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-7259?format=md#impact-score)

Toggle side navigation

## Description

An authorized user can issue queries with duplicate \_id fields, that leads
to unexpected behavior in MongoDB Server, which may result to crash. This
issue can only be triggered by authorized users and cause Denial of
Service. This issue affects MongoDB Server v8.1 version 8.1.0.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-7259?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mongodb | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |
| 14.04 LTS trusty | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-7259?format=md#patch-details)

## Notes

---

### [john-breton](https://launchpad.net/~john-breton)

Patches were released after the switch to SSPL upstream,
as such we cannot use them to patch Ubuntu releases.
The hope is a license-compliant third-party will make
patches available in the future.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| mongodb | * Upstream:   [8e6cfbd](https://github.com/mongodb/mongo/commit/8e6cfbd72c7ed49df67cf6fb7b8000cc21cd9279) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-7259)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-7259)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-7259)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-7259)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-7259>
* <https://jira.mongodb.org/browse/SERVER-102693>
