{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "4.2.25.tuxcare.els10-r0:\n  - CVE-2025-14847 pre-auth heap memory disclosure via OP_COMPRESSED zlib path",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677",
        "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.23/advisories/2026/clsa-2026_1780712677.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-08T10:40:21Z",
      "generator": {
        "date": "2026-06-08T10:40:21Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1780712677",
      "initial_release_date": "2026-06-06T02:24:45Z",
      "revision_history": [
        {
          "date": "2026-06-06T02:24:45Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-08T10:40:21Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "mongodb4.2: Fix of 3 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.23",
                "product": {
                  "name": "Alpine Linux 3.23",
                  "product_id": "Alpine-Linux-3.23",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.23:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els10-rr0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els10-rr0?arch=x86_64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
                "product": {
                  "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
                  "product_id": "mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2@4.2.25.tuxcare.els10-rr0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
                "product": {
                  "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
                  "product_id": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb4.2-openrc@4.2.25.tuxcare.els10-rr0?arch=aarch64&os_name=alpine&os_version=3.23"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64"
        },
        "product_reference": "mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64 as a component of Alpine Linux 3.23",
          "product_id": "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64"
        },
        "product_reference": "mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.23"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-6710",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5.\n\nThe same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-6710"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106749",
          "url": "https://jira.mongodb.org/browse/SERVER-106749"
        }
      ],
      "release_date": "2025-06-26T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-06T02:24:45.090392Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2025-10059",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v8.0 versions prior to 8.0.6.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-10059"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100901",
          "url": "https://jira.mongodb.org/browse/SERVER-100901"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-100909",
          "url": "https://jira.mongodb.org/browse/SERVER-100909"
        }
      ],
      "release_date": "2025-09-05T21:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-06T02:24:45.090392Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2025-14847",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "category": "description",
          "text": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
          "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-docker/cve/CVE-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-115508",
          "url": "https://jira.mongodb.org/browse/SERVER-115508"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/12/29/21",
          "url": "http://www.openwall.com/lists/oss-security/2025/12/29/21"
        },
        {
          "category": "external",
          "summary": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847",
          "url": "https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server",
          "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847"
        }
      ],
      "release_date": "2025-12-19T11:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-06T02:24:45.090392Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677",
          "product_ids": [
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-4.2.25.tuxcare.els10-rr0.x86_64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.aarch64",
            "Alpine-Linux-3.23:mongodb4.2-openrc-4.2.25.tuxcare.els10-rr0.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-docker/releases/CLSA-2026:1780712677"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}