Cyber Security News

Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression

A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication.

The flaw resides in MongoDB’s zlib compression implementation and affects multiple versions of the database platform.​

The vulnerability enables client-side exploitation of the MongoDB Server’s zlib implementation. Potentially exposing sensitive data stored in uninitialized heap memory.

What makes this flaw particularly dangerous is that attackers can exploit it without authenticating to the server, significantly lowering the barrier for malicious actors.​

The vulnerability impacts a wide range of MongoDB versions, spanning several major releases:​

ProductAffected Versions
MongoDB8.2.0 through 8.2.2
MongoDB8.0.0 through 8.0.16
MongoDB7.0.0 through 7.0.26
MongoDB6.0.0 through 6.0.26
MongoDB5.0.0 through 5.0.31
MongoDB4.4.0 through 4.4.29
MongoDBAll versions of 4.2
MongoDBAll versions of 4.0
MongoDBAll versions of 3.6

MongoDB strongly recommends upgrading to the patched versions  8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.​

For organizations that cannot upgrade immediately, MongoDB recommends a temporary workaround.

Disable zlib compression by configuring mongod or mongos to omit zlib in the networkMessageCompressors or net. Compression/compressor settings: Use safe alternatives such as Snappy or Zstd, or turn off compression.

Exposing uninitialized heap memory can lead to information disclosure. Potentially revealing sensitive database contents, cryptographic keys, or other confidential data residing in server memory.

Security teams should prioritize patching MongoDB installations immediately to prevent potential data breaches.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago