yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-14911
Component Overview
Vulnerability Overview
Name
CVE-2025-14911
Source
NVD (
link
)
Debian (
link
)
Description
User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overflow the bounding container.
CWEs
CWE-120
Published Date
Jan 27, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
mongodb
False Positive
Vulnerability Ratings
#
7.1
CVSSv4
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
mongodb
yocto
kirkstone
4.4.13
Not Affected
mongodb
yocto
master
4.4.24
Not Affected