Critical MongoDB Vulnerability Allows Unauthenticated Attackers to Read Server Memory
553/68 Monday, December 29, 2025 A serious security vulnerability has been identified in MongoDB, tracked as CVE-2025-14847, with a CVSS score of 8.7. The flaw could allow unauthenticated remote attackers to read uninitialized heap memory from a MongoDB server. The issue stems from inconsistent handling of the length parameter in MongoDB’s Zlib-based network compression protocol, […]
