Friday, October 2, 2026

Pre-Auth Flaw in MongoDB Server Allows Attackers to Cause DoS

A critical pre-authentication vulnerability (CVE-2025-6709) in MongoDB Server enables unauthenticated attackers to trigger denial-of-service (DoS) conditions by exploiting improper input validation in OIDC authentication.

The flaw allows malicious actors to crash database servers by sending specially crafted JSON payloads containing specific date values, causing invariant failures and server crashes.

 This vulnerability affects MongoDB Server versions before 7.0.17, 8.0.5, and 6.0.21 (with authentication required for 6.x exploitation).

Vulnerability Analysis

Attackers can reproduce the exploit using MongoDB’s mongo shell to send malicious JSON payloads targeting the OIDC authentication mechanism.

The server fails to properly validate date values in JSON input, leading to:

  • Complete server crashes without authentication in v7.0 and v8.0 deployments
  • Post-authentication DoS in v6.0 environments
  • Critical disruption of database operations through invariant failures

The vulnerability carries a CVSS score of 7.5 (High) due to its network-based attack vector, low attack complexity, and high availability impact. 

MongoDB has classified this as CWE-20 (Improper Input Validation).

The OIDC flaw follows multiple security issues disclosed in MongoDB this year:

CVE IDDescriptionCVSSAffected VersionsFixed Versions
CVE-2025-6709Pre-auth DoS via OIDC date handling7.5v6.0 <6.0.21, v7.0 <7.0.17, v8.0 <8.0.56.0.21/7.0.17/8.0.5

Mitigation and Updates

Administrators should immediately upgrade to patched versions:

  • MongoDB v6.0 → 6.0.21 or later
  • MongoDB v7.0 → 7.0.17 or later
  • MongoDB v8.0 → 8.0.5 or later

For environments where immediate patching isn’t feasible, consider disabling OIDC authentication until updates are applied.

MongoDB has confirmed no known active exploits currently target this vulnerability, but proof-of-concept reproduction is confirmed via the mongo shell.

This vulnerability highlights persistent risks in database authentication mechanisms, particularly as enterprises increasingly adopt OIDC for cloud-native deployments.

The discovery follows multiple MongoDB vulnerabilities disclosed in 2025, including certificate validation bypasses (CVE-2025-3085) and unauthenticated DoS flaws (CVE-2025-3083). 

Database administrators should prioritize patch cycles and monitor authentication logs for anomalous JSON payloads containing date objects.

Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA

A phishing-as-a-service operation dubbed Milk Dragon, also known as...

12 Best SSO Solutions Compared (2026): Features & Pricing

Microsoft Entra ID is the best SSO for M365-licensed...

Windows 11 26H2 Enables Settings Backup by Default for Eligible Devices

Microsoft has automatically enabled Windows settings backup for eligible...

12 Best IGA Tools Compared (2026): Features & Pricing

SailPoint remains the best overall IGA platform for certification...

11 Best PAM Solutions Compared (2026): Features & Pricing

CyberArk remains the best overall PAM platform for depth-driven...

12 Best IAM Solutions Compared (2026): Features & Pricing

For workforce identity, Microsoft Entra ID is the best...

10 Best Container Registry Security Tools Compared (2026): Features & Pricing

The best container registry security stack in 2026 starts...

China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacks

A China-linked threat actor known as TA419 has targeted...

Related Articles

Recent News