logo

How to find MongoDB instances on your network

ID: f9928010-f002-5bf7-b5ed-d18810057c2f

STIX ID: report--f9928010-f002-5bf7-b5ed-d18810057c2f

Feed Name: runZero Blog

Threat Score
78/100

Date Published: 2025-12-24

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

MongoDB disclosed a high-severity pre-authentication memory-leak vulnerability (CVE-2025-14847, CVSS 7.5) caused by mismatched length fields in Zlib-compressed protocol headers that can expose uninitialized heap memory and sensitive data. The advisory lists many affected server versions (3.6.x through 8.2.x with specific upgrade cutoffs), states there is evidence of active exploitation, and urges immediate upgrades to the provided patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.