{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_docker/alpinelinux3.22/vex/2025/cve-2025-6710-els_docker-alpinelinux3_22.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-01-29T16:56:09Z",
      "generator": {
        "date": "2026-01-29T16:56:09Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-6710-ELS_DOCKER-ALPINELINUX3.22",
      "initial_release_date": "2025-06-26T14:15:00Z",
      "revision_history": [
        {
          "date": "2025-06-26T14:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-01-29T16:56:09Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-6710"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.22",
                "product": {
                  "name": "Alpine Linux 3.22",
                  "product_id": "Alpine-Linux-3.22",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.22:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26-rr0.aarch64",
                "product": {
                  "name": "mongodb6-6.0.26-rr0.aarch64",
                  "product_id": "mongodb6-6.0.26-rr0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26-rr0?arch=aarch64&os_name=alpine&os_version=3.22"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26-rr0.aarch64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26-rr0.aarch64",
                  "product_id": "mongodb6-openrc-6.0.26-rr0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26-rr0?arch=aarch64&os_name=alpine&os_version=3.22"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "mongodb6-6.0.26-rr0.x86_64",
                "product": {
                  "name": "mongodb6-6.0.26-rr0.x86_64",
                  "product_id": "mongodb6-6.0.26-rr0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6@6.0.26-rr0?arch=x86_64&os_name=alpine&os_version=3.22"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "mongodb6-openrc-6.0.26-rr0.x86_64",
                "product": {
                  "name": "mongodb6-openrc-6.0.26-rr0.x86_64",
                  "product_id": "mongodb6-openrc-6.0.26-rr0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/mongodb6-openrc@6.0.26-rr0?arch=x86_64&os_name=alpine&os_version=3.22"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26-rr0.aarch64 as a component of Alpine Linux 3.22",
          "product_id": "Alpine-Linux-3.22:mongodb6-6.0.26-rr0.aarch64"
        },
        "product_reference": "mongodb6-6.0.26-rr0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.22"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-6.0.26-rr0.x86_64 as a component of Alpine Linux 3.22",
          "product_id": "Alpine-Linux-3.22:mongodb6-6.0.26-rr0.x86_64"
        },
        "product_reference": "mongodb6-6.0.26-rr0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.22"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26-rr0.aarch64 as a component of Alpine Linux 3.22",
          "product_id": "Alpine-Linux-3.22:mongodb6-openrc-6.0.26-rr0.aarch64"
        },
        "product_reference": "mongodb6-openrc-6.0.26-rr0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.22"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mongodb6-openrc-6.0.26-rr0.x86_64 as a component of Alpine Linux 3.22",
          "product_id": "Alpine-Linux-3.22:mongodb6-openrc-6.0.26-rr0.x86_64"
        },
        "product_reference": "mongodb6-openrc-6.0.26-rr0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.22"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-6710",
      "cwe": {
        "id": "CWE-674",
        "name": "Uncontrolled Recursion"
      },
      "notes": [
        {
          "category": "description",
          "text": "MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5.\n\nThe same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Alpine-Linux-3.22:mongodb6-6.0.26-rr0.aarch64",
          "Alpine-Linux-3.22:mongodb6-6.0.26-rr0.x86_64",
          "Alpine-Linux-3.22:mongodb6-openrc-6.0.26-rr0.aarch64",
          "Alpine-Linux-3.22:mongodb6-openrc-6.0.26-rr0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-6710"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SERVER-106749",
          "url": "https://jira.mongodb.org/browse/SERVER-106749"
        }
      ],
      "release_date": "2025-06-26T14:15:00Z"
    }
  ]
}