Sunday, January 18, 2026
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Gaming
  • Sports
No Result
View All Result
  • Home
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Gaming
  • Sports
No Result
View All Result
Australia Pitch
No Result
View All Result
Home Europe

MongoDB urgent patch: vulnerability under attack, public PoC exploit

December 30, 2025

A recently patched and publicly disclosed security vulnerability in MongoDB, which threatens the theft of confidential data, has been actively used in attacks. The publication of the PoC has increased the threat; Administrators should update the product as soon as possible.

The cause of the CVE-2025-14847 issue, codenamed MongoBleed, is a logic error in the zlib data decompression implementation, which also occurs before authentication.

Upon receiving a message from the client, the MongoDB server blindly trusts the size of the data specified during the transfer and, therefore, may return the contents of an uninitialized heap.

Therefore, by sending multiple requests to the server, an unauthorized attacker will be able to obtain sensitive information such as internal state and pointers. No need to interact with legitimate users.

The vulnerability received a CVSS score of 8.7, affecting multiple versions of the MongoDB DBMS, both supported and obsolete. The threat is also related to Ubuntu.

The patch released this month comes in builds 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32 and 4.4.30. Due to ongoing attacks as well as the publication of PoC code on GitHub, users are advised to update as soon as possible.

If this is not possible, you can temporarily disable zlib, limit access to the MongoDB server over the network, and monitor logs for unusual unauthorized connections.

An internet scan conducted by Censys identified more than 87,000 potentially vulnerable MongoDB instances, with the highest concentration in the US, China and Germany.

Next Post

WP: Musk abandoned the idea of ​​forming his own party under Vance's influence

Recommended.

Valve has released Beta version of Steam with new design and improved

Valve has released Beta version of Steam with new design and improved

July 29, 2025
A carbon monoxide leak occurred at a factory in Australia, injuring 21 people.

A carbon monoxide leak occurred at a factory in Australia, injuring 21 people.

December 2, 2025
Maria Zakharova talked about those who want to move to Russia by American and European citizens

Maria Zakharova talked about those who want to move to Russia by American and European citizens

August 21, 2025
In the first hours of the new year, a young girl was swept out to sea and died.

In the first hours of the new year, a young girl was swept out to sea and died.

January 2, 2026

The provision for using Russian assets for recovery has disappeared from the plan for Ukraine.

November 25, 2025
The zoo caregiver has a broken neck when feeding LVIV, and does not survive

The zoo caregiver has a broken neck when feeding LVIV, and does not survive

September 11, 2025
The US claims the CIA dreams of war between Russia and NATO

The US claims the CIA dreams of war between Russia and NATO

December 21, 2025
Kingdom Come: Deliverance 2's final DLC trailer about the church – released November 11

Kingdom Come: Deliverance 2's final DLC trailer about the church – released November 11

October 25, 2025
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Sports
  • Gaming
  • Press release

© 2025 Australia Pitch

No Result
View All Result
  • Home
  • National
  • USA
  • Europe
  • Gaming
  • Opinion
  • Sports
  • Society
  • Press release

© 2025 Australia Pitch