New MongoDB Vulnerability Allows Attackers to Crash Servers, Exposing Critical Data
ID: e828b0f9-f998-55b6-87d5-04dbcc169f7f
STIX ID: report--e828b0f9-f998-55b6-87d5-04dbcc169f7f
Feed Name: GBHackers
**CVE-2026-25611 — MongoDB OP_COMPRESSED DoS:** A high-severity unauthenticated denial-of-service vulnerability in MongoDB's OP_COMPRESSED wire protocol lets attackers send small compressed packets that claim a large uncompressed size, forcing excessive memory allocation and crashing mongod processes; it affects compression-enabled MongoDB versions (patched in 7.0.29, 8.0.18, 8.2.4), is trivially exploitable over port 27017, potentially impacts hundreds of thousands of internet-exposed instances, and should be mitigated by immediate patching, restricting access, and applying OS memory limits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
