In MongoDB Server versions 7.0 prior to 7.0.26, 8.0 prior to 8.0.16, and 8.2 prior to 8.2.2 a medium severity vulnerability CVE-2025-12893 was detected. This vulnerability allows MongoDB servers running on Windows or Apple platforms to successfully complete TLS handshakes with client or server certificates that do not meet the documented Extended Key Usage (EKU) requirements. Specifically, certificates missing the clientAuth EKU may still authenticate as clients, and on Apple servers, certificates missing the serverAuth EKU may still authenticate as servers during egress TLS connections. To address this issue, users should upgrade MongoDB Server to versions 7.0.26, 8.0.16, or 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12893.
MongoDB: TLS Certificate Validation Bypass on Windows and Apple Servers
by the Hossted team
25.11.2025