Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory
Identity

New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory

userBy userDecember 27, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 27, 2025Ravi LakshmananDatabase security/vulnerabilities

MongoDB flaws

A high-severity security flaw has been identified in MongoDB that could allow an unauthenticated user to read uninitialized heap memory.

The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), is described as a case of improper handling of length parameter mismatch. Length parameter mismatch occurs when a program fails to adequately handle scenarios where the length field does not match the actual length of the associated data.

According to the flaw description on CVE.org, “A mismatch in the length field of the Zlib compression protocol header could allow an uninitialized heap memory read by an unauthenticated client.”

cyber security

This flaw affects the following versions of the database:

MongoDB 8.2.0 to 8.2.3 MongoDB 8.0.0 to 8.0.16 MongoDB 7.0.0 to 7.0.26 MongoDB 6.0.0 to 6.0.26 MongoDB 5.0.0 to 5.0.31 MongoDB 4.4.0 to 4.4.29 All MongoDB servers v4.2 versions All MongoDB Server v4.0 version All MongoDB servers v3.6 version

This issue was resolved in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30.

“Client-side abuse of the server’s zlib implementation could result in uninitialized heap memory being returned without authentication to the server,” MongoDB said. “We strongly recommend that you upgrade to the fixed version as soon as possible.”

cyber security

If immediate updates are not an option, we recommend disabling zlib compression on your MongoDB server by starting mongod or mongos with the networkMessageCompressors or net.compression.compressors options that explicitly omit zlib. Other compression options supported by MongoDB are snappy and zstd.

“CVE-2025-14847 allows a remote unauthenticated attacker to cause a condition in which the MongoDB server may return uninitialized memory from the heap,” OP Innovate said. “This could potentially expose sensitive data in memory, including internal state information, pointers, or other data that could aid further exploitation by an attacker.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow reality crushed Ÿnsect, a French startup that raised more than $600 million for insect farming
Next Article Eye denture surgery, ‘blood chimerism’ and pregnancy from oral sex: 12 bad medical cases we covered in 2025
user
  • Website

Related Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

December 30, 2025

How to integrate AI into modern SOC workflows

December 30, 2025

Mustang Panda uses signed kernel-mode rootkit to load TONESHELL backdoor

December 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

The year AI moves from experimentation to execution

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.