#cve-2025-14847

[ follow ]
#mongodb
fromThe Hacker News
4 days ago
Information security

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

A zlib decompression flaw (CVE-2025-14847, MongoBleed) allows unauthenticated remote memory disclosure in default-enabled MongoDB, exposing sensitive data from many internet-exposed instances.
fromThe Hacker News
6 days ago
Information security

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

A zlib-related length-handling bug in MongoDB (CVE-2025-14847) can let unauthenticated clients read uninitialized heap memory; update recommended.
[ Load more ]