InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory
Technology

New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory

December 28, 2025 2 Min Read
Share

A high-severity security flaw has been identified in MongoDB that could allow an unauthenticated user to read uninitialized heap memory.

Vulnerabilities are tracked as follows CVE-2025-14847 (CVSS score: 8.7) is described as a case of improper handling of length parameter mismatch. This occurs when the program cannot properly handle scenarios where the length field does not match the actual length of the associated data.

According to the flaw description on CVE.org, “A mismatch in the length field of the Zlib compression protocol header could allow an uninitialized heap memory read by an unauthenticated client.”

This flaw affects the following versions of the database:

  • MongoDB 8.2.0 – 8.2.3
  • MongoDB 8.0.0 to 8.0.16
  • MongoDB 7.0.0 to 7.0.26
  • MongoDB 6.0.0 to 6.0.26
  • MongoDB 5.0.0 to 5.0.31
  • MongoDB 4.4.0 to 4.4.29
  • All MongoDB servers v4.2 versions
  • All versions of MongoDB server v4.0
  • All MongoDB servers v3.6 versions

This issue was resolved in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30.

“Client-side abuse of the server’s zlib implementation could result in uninitialized heap memory being returned without authentication to the server,” MongoDB said. “We strongly recommend that you upgrade to the fixed version as soon as possible.”

If immediate updates are not an option, we recommend disabling zlib compression on your MongoDB server by starting mongod or mongos with the networkMessageCompressors or net.compression.compressors options that explicitly omit zlib. Other compression options supported by MongoDB are snappy and zstd.

“CVE-2025-14847 allows a remote unauthenticated attacker to cause a condition in which the MongoDB server may return uninitialized memory from the heap,” OP Innovate said. “This could potentially expose sensitive data in memory, including internal state information, pointers, or other data that could aid further exploitation by an attacker.”

See also  One click allows you to turn Perplexity's Comet AI Browser into Data Thief
Share This Article
Twitter Copy Link
Previous Article Get up to 92% off Sniper Elite games and DLC now Get up to 92% off Sniper Elite games and DLC now
Next Article Republicans unite behind Vance as Trump privately refuses to run for third term Republicans unite behind Vance as Trump privately refuses to run for third term

You Might Also Like

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China
Technology

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

5 Min Read
WhatsApp Worm, Critical CVE, Oracle 0-Day, Ransomware Cartel, and More
Technology

WhatsApp Worm, Critical CVE, Oracle 0-Day, Ransomware Cartel, and More

25 Min Read
SVG and PureRAT Phishing
Technology

Researchers reveal SVG and Purerat phishing threats targeting Ukraine and Vietnam

4 Min Read
From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools
Technology

From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools

8 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?