logo

MongoDB warns admins to patch severe RCE flaw immediately

ID: 43f9739f-bb76-5225-817f-0a63699af838

STIX ID: report--43f9739f-bb76-5225-817f-0a63699af838

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-12-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

MongoDB disclosed CVE-2025-14847, a high-severity memory-read vulnerability in the Server's zlib implementation that can return uninitialized heap memory to unauthenticated remote attackers; administrators are urged to upgrade affected MongoDB versions or disable zlib compression immediately, with fixed releases provided for multiple major versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.