Vulnerability Management, Patch/Configuration Management, Threat Management, Threat Intelligence

MongoDB issues urgent warning over RCE security flaw

BleepingComputer reports that MongoDB has advised the urgent patching of the high-severity flaw, tracked as CVE-2025-14847, which could be abused to allow remote code execution and server takeovers.

Multiple versions of the widely used non-relational database management system are affected by the issue, according to MongoDB, which recommended immediate upgrades to versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.

"An client-side exploit of the Server's zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible," said MongoDB.

MongoDB has also advised the administrators to disable zlib compression as a temporary protection if upgrading is not immediately possible.

Such an advisory comes six years after the Cybersecurity and Infrastructure Security Agency warned of the active exploitation of a MongoDB mongo-express RCE flaw, tracked as CVE-2019-10758.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds