MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.mongodb.org/browse/SERVER-95524 |
![]() ![]() |
History
Sun, 07 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mongodb
Mongodb mongodb |
|
Vendors & Products |
Mongodb
Mongodb mongodb |
Fri, 05 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 05 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management. This issue affects MongoDB Server v6.0 versions prior to 6.0.25, MongoDB Server v7.0 versions prior to 7.0.22 and MongoDB Server v8.0 versions prior to 8.0.12 | |
Title | MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation | |
Weaknesses | CWE-672 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mongodb
Published: 2025-09-05T20:39:14.188Z
Updated: 2025-09-05T21:08:05.687Z
Reserved: 2025-09-05T20:28:10.874Z
Link: CVE-2025-10060

Updated: 2025-09-05T21:07:24.616Z

Status : Awaiting Analysis
Published: 2025-09-05T21:15:34.980
Modified: 2025-09-08T16:25:38.810
Link: CVE-2025-10060

No data.