• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

MongoDB Vulnerability CVE-2025-14847 Below Energetic Exploitation Worldwide

Admin by Admin
December 29, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Dec 29, 2026Ravie LakshmananDatabase Safety / Vulnerability

A lately disclosed safety vulnerability in MongoDB has come beneath energetic exploitation within the wild, with over 87,000 doubtlessly prone cases recognized internationally.

The vulnerability in query is CVE-2025-14847 (CVSS rating: 8.7), which permits an unauthenticated attacker to remotely leak delicate information from the MongoDB server reminiscence. It has been codenamed MongoBleed.

“A flaw in zlib compression permits attackers to set off info leakage,” OX Safety mentioned. “By sending malformed community packets, an attacker can extract fragments of personal information.”

Cybersecurity

The issue is rooted in MongoDB Server’s zlib message decompression implementation (“message_compressor_zlib.cpp”). It impacts cases with zlib compression enabled, which is the default configuration. Profitable exploitation of the shortcoming might enable an attacker to extract delicate info from MongoDB servers, together with person info, passwords, and API keys.

“Though the attacker may have to ship a considerable amount of requests to assemble the complete database, and a few information is perhaps meaningless, the extra time an attacker has, the extra info may very well be gathered,” OX Safety added.

Cloud safety firm Wiz mentioned CVE-2025-14847 stems from a flaw within the zlib-based community message decompression logic, enabling an unauthenticated attacker to ship malformed, compressed community packets to set off the vulnerability and entry uninitialized heap reminiscence with out legitimate credentials or person interplay.

“The affected logic returned the allotted buffer measurement (output.size()) as a substitute of the particular decompressed information size, permitting undersized or malformed payloads to reveal adjoining heap reminiscence,” safety researchers Merav Bar and Amitai Cohen mentioned. “As a result of the vulnerability is reachable previous to authentication and doesn’t require person interplay, Web-exposed MongoDB servers are notably in danger.”

Information from assault floor administration firm Censys reveals that there are greater than 87,000 doubtlessly weak cases, with a majority of them positioned within the U.S., China, Germany, India, and France. Wiz famous that 42% of cloud environments have no less than one occasion of MongoDB in a model weak to CVE-2025-14847. This contains each internet-exposed and inner sources.

Cybersecurity

The precise particulars surrounding the character of assaults exploiting the flaw are presently unknown. Customers are suggested to replace to MongoDB variations 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30. Patches for MongoDB Atlas have been utilized. It is price noting that the vulnerability additionally impacts the Ubuntu rsync bundle, because it makes use of zlib.

As momentary workarounds, it is really helpful to disable zlib compression on the MongoDB Server by beginning mongod or mongos with a networkMessageCompressors or a web.compression.compressors choice that explicitly omits zlib. Different mitigations embrace limiting community publicity of MongoDB servers and monitoring MongoDB logs for anomalous pre-authentication connections.

Tags: ActiveCVE202514847ExploitationMongoDBVulnerabilityworldwide
Admin

Admin

Next Post
Optimizing Java Purposes for Arm64 within the Cloud

Optimizing Java Purposes for Arm64 within the Cloud

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

GitGuardian Raises $50M to Deal with AI Agent & Identification Safety

GitGuardian Raises $50M to Deal with AI Agent & Identification Safety

February 11, 2026
Fitbit’s Gemini-Powered Coach Is Coming to iPhone and Different International locations

Fitbit’s Gemini-Powered Coach Is Coming to iPhone and Different International locations

February 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved