By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
Computing

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

News Room
Last updated: 2025/12/27 at 3:19 AM
News Room Published 27 December 2025
Share
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
SHARE

Dec 27, 2025Ravie LakshmananDatabase Security / Vulnerability

A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory.

The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling of length parameter inconsistency, which arises when a program fails to appropriately tackle scenarios where a length field is inconsistent with the actual length of the associated data.

“Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client,” according to a description of the flaw in CVE.org.

Cybersecurity

The flaw impacts the following versions of the database –

  • MongoDB 8.2.0 through 8.2.3
  • MongoDB 8.0.0 through 8.0.16
  • MongoDB 7.0.0 through 7.0.26
  • MongoDB 6.0.0 through 6.0.26
  • MongoDB 5.0.0 through 5.0.31
  • MongoDB 4.4.0 through 4.4.29
  • All MongoDB Server v4.2 versions
  • All MongoDB Server v4.0 versions
  • All MongoDB Server v3.6 versions

The issue has been addressed in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30.

“An client-side exploit of the Server’s zlib implementation can return uninitialized heap memory without authenticating to the server,” MongoDB said. “We strongly recommend upgrading to a fixed version as soon as possible.”

Cybersecurity

If immediate update is not an option, it’s recommended to disable zlib compression on the MongoDB Server by starting mongod or mongos with a networkMessageCompressors or a net.compression.compressors option that explicitly omits zlib. The other compressor options supported by MongoDB are snappy and zstd.

“CVE-2025-14847 allows a remote, unauthenticated attacker to trigger a condition in which the MongoDB server may return uninitialized memory from its heap,” OP Innovate said. “This could result in the disclosure of sensitive in-memory data, including internal state information, pointers, or other data that may assist an attacker in further exploitation.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Deals: 24GB M4 MacBook Air 0 off, Apple Pencil Pro, more 9to5Mac Deals: 24GB M4 MacBook Air $300 off, Apple Pencil Pro, more 9to5Mac
Next Article Cloudflare Open Sources tokio‑quiche, Promising Easier QUIC and HTTP/3 in Rust Cloudflare Open Sources tokio‑quiche, Promising Easier QUIC and HTTP/3 in Rust
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Why you don’t want an Apple Screen Time Wrapped year in review
Why you don’t want an Apple Screen Time Wrapped year in review
Gadget
Make your AI bills disappear forever with this one AI hub
Make your AI bills disappear forever with this one AI hub
News
Linux 6.19 Lands Fix For ARM64 EFI Systems Crashing On Boot
Linux 6.19 Lands Fix For ARM64 EFI Systems Crashing On Boot
Computing
The best Samsung accessories for your new Galaxy S25
The best Samsung accessories for your new Galaxy S25
News

You Might also Like

Linux 6.19 Lands Fix For ARM64 EFI Systems Crashing On Boot
Computing

Linux 6.19 Lands Fix For ARM64 EFI Systems Crashing On Boot

1 Min Read
What did global mobility look like for Africa’s tech workers in 2025?
Computing

What did global mobility look like for Africa’s tech workers in 2025?

12 Min Read
QNX Self-Hosted Developer Desktop Brings QNX 8.0 To A Wayland + Xfce Desktop
Computing

QNX Self-Hosted Developer Desktop Brings QNX 8.0 To A Wayland + Xfce Desktop

2 Min Read
Bitunix Ranked Among the World’s Top 7 Exchanges by Volume in CoinGlass 2025 Report | HackerNoon
Computing

Bitunix Ranked Among the World’s Top 7 Exchanges by Volume in CoinGlass 2025 Report | HackerNoon

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?