CVE-2026-25612Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-412

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 102-1002-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25612 MongoDB Resource Lock Collision Vulnerability Causing Unintended Collection Unavailability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25612

    Post summary

    The text announces the discovery of a MongoDB resource lock collision vulnerability that can render collections unavailable, without providing any PoC, exploit, patch, or evidence of active exploitation.

    0001079
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25612 The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently co… https://www.cve.org/CVERecord?id=CVE-2026-25612

    Post summary

    The snippet offers a concise disclosure of a MongoDB internal locking vulnerability, without evidence of active exploitation, PoC, or mitigation.

    0001096
    56.5K followersView on X

Explore more