Saturday, January 17, 2026
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Gaming
  • Sports
No Result
View All Result
  • Home
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Gaming
  • Sports
No Result
View All Result
Australia Pitch
No Result
View All Result
Home Europe

MongoDB urgent patch: vulnerability under attack, public PoC exploit

December 30, 2025

A recently patched and publicly disclosed security vulnerability in MongoDB, which threatens the theft of confidential data, has been actively used in attacks. The publication of the PoC has increased the threat; Administrators should update the product as soon as possible.

The cause of the CVE-2025-14847 issue, codenamed MongoBleed, is a logic error in the zlib data decompression implementation, which also occurs before authentication.

Upon receiving a message from the client, the MongoDB server blindly trusts the size of the data specified during the transfer and, therefore, may return the contents of an uninitialized heap.

Therefore, by sending multiple requests to the server, an unauthorized attacker will be able to obtain sensitive information such as internal state and pointers. No need to interact with legitimate users.

The vulnerability received a CVSS score of 8.7, affecting multiple versions of the MongoDB DBMS, both supported and obsolete. The threat is also related to Ubuntu.

The patch released this month comes in builds 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32 and 4.4.30. Due to ongoing attacks as well as the publication of PoC code on GitHub, users are advised to update as soon as possible.

If this is not possible, you can temporarily disable zlib, limit access to the MongoDB server over the network, and monitor logs for unusual unauthorized connections.

An internet scan conducted by Censys identified more than 87,000 potentially vulnerable MongoDB instances, with the highest concentration in the US, China and Germany.

Next Post

WP: Musk abandoned the idea of ​​forming his own party under Vance's influence

Recommended.

A 5.5 earthquake occurs in Kamchatka

A 5.5 earthquake occurs in Kamchatka

August 13, 2025

Shafaq News: More than 230 families of the veterans brought Iraq from a camp in Syria

September 1, 2025
Europe is left “at home alone”

Europe is left “at home alone”

January 1, 2026
Fraudsters began informing Russians about unpaid taxes

Fraudsters began informing Russians about unpaid taxes

December 5, 2025
Leo XIV was skeptical about the possibility of a trip to Ukraine

Leo XIV was skeptical about the possibility of a trip to Ukraine

December 10, 2025

Telegraph: nearly 100 thousand young Ukrainians have left the country since the end of August

October 30, 2025

Australia was hit by a sandstorm

December 4, 2025
A series of explosions occurred in Russia

A series of explosions occurred in Russia

August 31, 2025
  • National
  • Society
  • USA
  • Europe
  • Opinion
  • Sports
  • Gaming
  • Press release

© 2025 Australia Pitch

No Result
View All Result
  • Home
  • National
  • USA
  • Europe
  • Gaming
  • Opinion
  • Sports
  • Society
  • Press release

© 2025 Australia Pitch


Warning: array_sum() expects parameter 1 to be array, null given in /www/wwwroot/aupitch.com/wp-content/plugins/jnews-social-share/class.jnews-social-background-process.php on line 111