New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

by Anika Shah - Technology
0 comments

MongoDB Vulnerability Allows Unauthenticated Heap Memory Read

A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory.

The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling of length parameter inconsistency, which arises when a program fails to appropriately tackle scenarios where a length field is inconsistent with the actual length of the associated data.

“Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client,” according to a description of the flaw in CVE.org.

Publication Date: 2025/12/27 08:11:10

Related Posts

Leave a Comment