Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression
ID: 85b8aba6-08bf-5d66-b504-9075ce610c26
STIX ID: report--85b8aba6-08bf-5d66-b504-9075ce610c26
Feed Name: cybersecurityNews.com
Threat Score
**CVE-2025-14847** — A critical unauthenticated vulnerability in MongoDB's zlib compression can allow remote clients to extract uninitialized heap memory and potentially disclose sensitive data (including cryptographic keys) across many MongoDB releases; MongoDB advises immediate upgrade to specified patched versions (e.g., 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, 4.4.30) or temporarily disable zlib compression and use alternatives like Snappy or Zstd.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
