logo

New MongoDB Vulnerability Lets Hackers Crash Any MongoDB Server

ID: 1724f014-6c93-5901-8b0a-b7f52daf4902

STIX ID: report--1724f014-6c93-5901-8b0a-b7f52daf4902

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

A high-severity MongoDB vulnerability (CVE-2026-25611, CVSS 7.5) allows unauthenticated attackers to crash compression-enabled MongoDB servers by sending small compressed packets that claim very large uncompressed sizes, producing massive memory amplification; the flaw affects compression-enabled versions (v3.4+, on by default since v3.6) including Atlas, with Shodan indicating ~207,000 exposed instances, and mitigations include immediate patching (8.2.4, 8.0.18, 7.0.29), disabling compression, tightening network access, and limiting connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.