Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 13, 2025

This PR contains the following updates:

Package Type Update Change
mongodb (source) dependencies patch 3.2.4 -> 3.2.5
mongodb (source) dependencies patch 3.2.3 -> 3.2.5

GitHub Vulnerability Alerts

CVE-2025-11695

When tlsInsecure=False appears in a connection string, certificate validation is disabled.

This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5.


Release Notes

mongodb/mongo-rust-driver (mongodb)

v3.2.5

Compare Source

The MongoDB Rust driver team is pleased to announce the v3.2.5 release of the mongodb crate, now available for download from crates.io.

This release fixes a bug that caused the driver to allow invalid TLS certificates when the URI option "tlsInsecure=false" was included in the connection string.

Full Release Notes

Bugfixes
  • RUST-2264 Fix handling of tlsInsecure in the URI (#​1453)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the renovate label Oct 13, 2025
@renovate renovate bot requested a review from a team as a code owner October 13, 2025 21:55
@renovate renovate bot merged commit 39c2a5d into main Oct 14, 2025
1 check passed
@renovate renovate bot deleted the renovate/crate-mongodb-vulnerability branch October 14, 2025 02:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants