logo

Cato CTRL™ Threat Research: New MongoDB Vulnerability Allows Instant Remote Server Takedown (CVE-2026-25611)

ID: 2fc8e7ad-e158-554c-ba07-e39de58eaf99

STIX ID: report--2fc8e7ad-e158-554c-ba07-e39de58eaf99

Feed Name: Cato Networks

Threat Score
78/100

Date Published: 2026-03-04

Date Updated: 2026-07-23

Author: Vitaly Simonovich

...
...

Cato CTRL disclosed CVE-2026-25611, a high-severity denial-of-service vulnerability in MongoDB's OP_COMPRESSED message handling where an attacker can claim a large uncompressedSize to force 48MB allocations per connection from small compressed packets (~47KB), leading to rapid OOM crashes; it affects MongoDB 3.4+ with compression enabled (default since 3.6), is demonstrably exploitable with minimal bandwidth against internet-exposed instances (~207k reported), and the report includes mitigations (patching, restricting access, disabling compression) and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.