BleepingComputer reports that MongoDB has advised the urgent patching of the high-severity flaw, tracked as CVE-2025-14847, which could be abused to allow remote code execution and server takeovers.
Multiple versions of the widely used non-relational database management system are affected by the issue, according to MongoDB, which recommended immediate upgrades to versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.
"An client-side exploit of the Server's zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible," said MongoDB.
MongoDB has also advised the administrators to disable zlib compression as a temporary protection if upgrading is not immediately possible.
Such an advisory comes six years after the Cybersecurity and Infrastructure Security Agency warned of the active exploitation of a MongoDB mongo-express RCE flaw, tracked as CVE-2019-10758.
Multiple versions of the widely used non-relational database management system are affected by the issue, according to MongoDB, which recommended immediate upgrades to versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.
"An client-side exploit of the Server's zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible," said MongoDB.
MongoDB has also advised the administrators to disable zlib compression as a temporary protection if upgrading is not immediately possible.
Such an advisory comes six years after the Cybersecurity and Infrastructure Security Agency warned of the active exploitation of a MongoDB mongo-express RCE flaw, tracked as CVE-2019-10758.




