Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-3085

MongoDB Server: intermediate certificates not checked for revocation on Linux

Technology

MongoDB

CVSS Score

9.8 / 10.0

Affected Versions

8.0 before 8.0.4; 7.0 before 7.0.16; 6.0 before 6.0.20; 5.0 before 5.0.31

Upstream Fix

8.0.4; 7.0.16; 6.0.20; 5.0.31

Published

April 1, 2025

OSSeva Coverage

Fixed upstream

Description

On Linux with TLS and CRL revocation checking enabled, MongoDB Server fails to check the revocation status of intermediate certificates in the peer's chain. With MONGODB-X509 authentication, which is not enabled by default, this may lead to improper authentication, and it may also affect intra-cluster authentication. NVD scores the record 9.8; MongoDB scores it 8.1.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.0 before 8.0.4; 7.0 before 7.0.16; 6.0 before 6.0.20; 5.0 before 5.0.31, you need this patch. Book a discovery call to get covered.