Datenbank-System MongoDB wird angegriffen

30. Dezember 2025

Das verbreitete Datenbank-System MongoDB weist diverse kritische Sicherheitslücken auf, die derzeit aktiv ausgenutzt werden.
Handeln ist dringend erforderlich!

Tracked as CVE-2025-14847, the flaw impacts the Zlib compression protocol and allows attackers to read uninitialized heap memory without authentication.

Patches for the bug were released on December 19, when MongoDB warned that successful exploitation could lead to memory leaks.

Dubbed MongoBleed, the issue can be abused via crafted compressed messages that, when parsed, cause the server to return the amount of allocated memory, and not the length of the decompressed data.

On Christmas Eve, Ox Security published a technical analysis of the security defect, explaining how it could be exploited to extract sensitive information from MongoDB servers.

Two days later, Elastic Security’s Joe Desimone released a PoC exploit for it, which can be used to extract session tokens, passwords, API keys, and other sensitive data.

Ox Security says the MongoDB vulnerability can be exploited to leak entire databases by sending multiple malformed requests.

According to Wiz, because the flawed network message decompression logic is processed before authentication, attackers can leak fragments of sensitive in-memory data without valid credentials or user interaction.

“Because the vulnerability is reachable prior to authentication and does not require user interaction, Internet-exposed MongoDB servers are particularly at risk,” Wiz notes.

MongoBleed exploited in the wild

Warning that the exploitation of MongoBleed started shortly after the PoC exploit was released, Wiz notes that roughly 42% of cloud environments have MongoDB instances that are vulnerable.

Censys observed more than 87,000 vulnerable MongoDB servers globally. According to security researcher Kevin Beaumont, there are over 200,000 instances.

“Because of how simple this is now to exploit — the bar is removed — expect high likelihood of mass exploitation and related security incidents,” Beaumont notes.

The vulnerability was patched in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30. Organizations should update self-managed instances as soon as possible or disable Zlib compression on the server to prevent exploitation.

Before updating, however, administrators should hunt for signs of compromise by checking the MongoDB server logs, Recon InfoSec co-founder Eric Capuano notes.lgemeine Verfügbarkeit soll bis Mitte Januar abgeschlossen sein.

Quelle: SecurityWeek

Ähnliche Beiträge

  • Windows 12 – kommt das neueste Betriebssystem noch 2026?

    21. Februar 2026 Windows 12 soll nach verschiedenen Gerüchten noch 2026 Windows 11 ablösen. Wir erklären, welche Gerüchte es zur neuen Windows-Version und deren Funktionen gibt und was es mit “Hudson Valley Next” und “CorePC” auf sich hat. Microsoft hat Windows 12 noch nicht offiziell angekündigt, doch es verdichten sich Leaks, interne Projektreferenzen und Aussagen aus dem Umfeld von Hardwarepartnern zum Erscheinen einer nicht mehr…

  • Windows 11 Updates-Zwang wird aufgehoben!

    25. März 2026 Microsoft beseitigt endlich eines der grössten Ärgernisse von Windows: Updates, die im unpassendsten Augenblick kommen. Bald können Sie Windows Update auf unbestimmte Zeit pausieren. Nach den jüngsten Problemen mit den Updates für Windows 11 werden viele die jüngste Erklärung von Pavan Davuluri, President for Microsoft’s Windows + Devices (W+D) Business, wohl als willkommene Nachricht empfinden. Davuluri gab nämlich in einem Blogbeitrag bekannt, dass Windows-Nutzer bald…

  • Wie Facebook-Mutterkonzern Meta 70 Milliarden US$ versenkte

    15. Januar 2026 Mit dem Metaverse versprach Meta eine Parallelwelt, die das Internet revolutionieren und neu denken sollte. Das Projekt entwickelte sich jedoch zum Rohrkrepierer. Mit 70 Milliarden Dollar Verlust zieht Meta nun die Konsequenzen. Das Metaverse hätte eigentlich das Internet revolutionieren, in gewisser Weise sogar ablösen sollen. Bis 2030 hätten sich laut Meta dort rund eine Milliarde Nutzer tummeln sollen. Die Analysten von Gartner waren 2022 gar noch…

  • Liechtenstein bekommt schnellstes Internet

    28. November 2025 Telecom Liechtenstein hat sein Glasfasernetz umgerüstet. Ab dem 9. Dezember wird ein 25 Gbit/s Internet angeboten. Telecom Liechtenstein bietet ab dem 9. Dezember flächendeckend für Haushalte und Unternehmen eine Internetverbindung von bis zu 25 Gbit/s. Laut Medienmitteilung ist Liechtenstein damit zum Land mit dem schnellsten Internet der Welt geworden. Das scheint auch so zu stimmen, wenn man die angegebene Geschwindigkeit mit dem…

  • Google bringt neuen Light-Browser “Disco”

    16. Dezember 2025 Google hat Disco vorgestellt, ein Testvehikel für die Zukunft des Webbrowsens. Eine erste Anwendung von Disco ist GenTabs, eine Funktion, die mittels KI eigenständig Web Apps für Suchanfragen baut. Google tüftelt in seinen Google Labs an einer neuen Art Browser, der unter dem Namen Disco entwickelt wird. Wie Google via Blog erklärt, soll Disco dazu dienen, neue Ansätze für das Browsen und Arbeiten im Internet zu…

  • Google’s QuickOffice lässt Office-Dokumente auf Smartphones editieren

    3. Januar 2026 Google has just made Quickoffice – its mobile app for creating and editing Microsoft Office documents – free for Android and iOS users. The app was bought by Google more than a year ago but previously cost $14.99 or $19.99 for the HD version. The search giant previously provided it for free to Google Apps for Business subscribers (a £3/month service that…