CVE-2026-25613
HighAdvisory
Published 10 Feb 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.1
- base score, highest
- EPSS
- 0.002
- 16th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 16
- of 17,781 indexed, latest versions
- Container images
- 13
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
An unsafe cast in the MongoDB query planner can result in a segmentation fault.
Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 13 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| mongodbbitnami | 7.0.5-3, 7.0.8-1, 7.0.14-1, 8.0.8-0+3 more | 7.0.29 | 7 |
| MongoDB (R)bitnami | 7.0.5-3, 7.0.8-1 | 7.0.29 | 2 |
| mongodbdeb | 1:3.6.3-0ubuntu1.4, 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3 | no fix listed | 6 |
- OSV records
- BIT-mongodb-2026-25613UBUNTU-CVE-2026-25613
Charts affected
16 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| codefreshcodefresh-onpremOfficialVerified publisher | 2.12.13 | 1 of 42See more | 14,956 |
| litmuslitmuschaos | 3.30.0 | 1 of 6See more | 7,007 |
| unifiunifiVerified publisher | 1.16.0 | 1 of 1See more | 7,268 |
| unifi-controllerqonstruktVerified publisher | 2.6.1 | 1 of 1See more | 10,469 |
| unifigeek-cookbookVerified publisher | 5.1.3 | 1 of 1See more | 11,839 |
| omada-controllergeek-cookbookVerified publisher | 4.4.2 | 1 of 1See more | 11,553 |
| mongodb-backupsinextraVerified publisher | 1.1.0 | 1 of 1See more | 4,238 |
| tocktock | 0.6.3 | 1 of 9See more | 12,907 |
| omada-controllerandrelote-k8sVerified publisher | 4.5.0 | 1 of 1See more | 11,553 |
| mongodbcowboysysopVerified publisher | 15.1.5 | 1 of 1See more | 6,161 |
| unifiegebackVerified publisher | 2.1.6 | 1 of 1See more | 7,268 |
| unifik8sonlabVerified publisher | 0.3.7 | 1 of 1See more | 7,268 |
| unifimidokura-communityVerified publisher | 0.0.6 | 1 of 1See more | 11,188 |
| mongodbpetersandor | 14.1.8 | 1 of 1See more | 4,109 |
| your-spotifyrubxkubeVerified publisher | 1.0.1 | 1 of 3See more | 5,066 |
| unifistartechnicaVerified publisher | 0.1.3 | 1 of 2See more | 14,493 |
Container images carrying it
13 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| jacobalberty/ | 896c0ab82d33 | mongodb | no fix listed | 3 |
| mbentley/ | f4e682274bed | mongodb | no fix listed | 2 |
| bitnamilegacy/ | 21e8f8baa432 | mongodb | 7.0.29 | 1 |
| bitnamilegacy/ | 2579e968033e | mongodb | 7.0.29 | 1 |
| bitnamilegacy/ | 3163c3842bfd | mongodb MongoDB (R) | 7.0.29 7.0.29 | 1 |
| bitnamilegacy/ | 6fe59ed5d79f | mongodb MongoDB (R) | 7.0.29 7.0.29 | 1 |
| bitnamilegacy/ | b0652af9c8d0 | mongodb | 7.0.29 | 1 |
| bitnami/ | b3bd5b6be9a0 | mongodb | 7.0.29 | 1 |
| jacobalberty/ | 4a3616625dda | mongodb | no fix listed | 1 |
| jacobalberty/ | b3edc809a3ff | mongodb | no fix listed | 1 |
| linuxserver/ | 0ae315a3a456 | mongodb | no fix listed | 1 |
| linuxserver/ | ab105cc50322 | mongodb | no fix listed | 1 |
| ghcr.io/ | 1eee8e20a87f | mongodb | 7.0.29 | 1 |