Datenbank-System MongoDB wird angegriffen

30. Dezember 2025

Das verbreitete Datenbank-System MongoDB weist diverse kritische Sicherheitslücken auf, die derzeit aktiv ausgenutzt werden.
Handeln ist dringend erforderlich!

Tracked as CVE-2025-14847, the flaw impacts the Zlib compression protocol and allows attackers to read uninitialized heap memory without authentication.

Patches for the bug were released on December 19, when MongoDB warned that successful exploitation could lead to memory leaks.

Dubbed MongoBleed, the issue can be abused via crafted compressed messages that, when parsed, cause the server to return the amount of allocated memory, and not the length of the decompressed data.

On Christmas Eve, Ox Security published a technical analysis of the security defect, explaining how it could be exploited to extract sensitive information from MongoDB servers.

Two days later, Elastic Security’s Joe Desimone released a PoC exploit for it, which can be used to extract session tokens, passwords, API keys, and other sensitive data.

Ox Security says the MongoDB vulnerability can be exploited to leak entire databases by sending multiple malformed requests.

According to Wiz, because the flawed network message decompression logic is processed before authentication, attackers can leak fragments of sensitive in-memory data without valid credentials or user interaction.

“Because the vulnerability is reachable prior to authentication and does not require user interaction, Internet-exposed MongoDB servers are particularly at risk,” Wiz notes.

MongoBleed exploited in the wild

Warning that the exploitation of MongoBleed started shortly after the PoC exploit was released, Wiz notes that roughly 42% of cloud environments have MongoDB instances that are vulnerable.

Censys observed more than 87,000 vulnerable MongoDB servers globally. According to security researcher Kevin Beaumont, there are over 200,000 instances.

“Because of how simple this is now to exploit — the bar is removed — expect high likelihood of mass exploitation and related security incidents,” Beaumont notes.

The vulnerability was patched in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30. Organizations should update self-managed instances as soon as possible or disable Zlib compression on the server to prevent exploitation.

Before updating, however, administrators should hunt for signs of compromise by checking the MongoDB server logs, Recon InfoSec co-founder Eric Capuano notes.lgemeine Verfügbarkeit soll bis Mitte Januar abgeschlossen sein.

Quelle: SecurityWeek

Ähnliche Beiträge

  • Google Passwd-Manager für Google Workspace

    24. Dezember 2025 Eine Anleitung für Benutzer von Firmen mit Google Workspace Passwd is designed specifically for organizations operating within Google Workspace. Rather than competing as a general consumer password manager, its purpose is narrow, and business-focused: secure credential storage, controlled sharing, and seamless Workspace integration. The platform emphasizes practicality over feature overload, aiming to provide a reliable system for teams that already rely on Google’s…

  • Russland blockiert Apples Facetime

    05. Dezember 2025 Russland geht gegen Apple vor Russia has blocked Apple’s (AAPL.O), opens new tab video-calling app FaceTime, the state communications watchdog said on Thursday, as part of an accelerating clampdown on foreign tech platforms that authorities allege are being used for criminal activity. The move follows restrictions against Google’s YouTube, Meta’s (META.O), opens new tab WhatsApp and the Telegram messaging service. The Reuters Tariff Watch newsletter is…

  • Neue Smartphones von Motorola – eine Alternative zu Samsung?

    3. März 2026 Mit dem Razr Fold präsentiert Motorola sein erstes faltbares Smartphone im Buchformat. Das Edge 70 Fusion wartet mit einem geschwungenen Display, einem Quad-Curve-Design und hochwertigen Materialien auf. Das Motorola Razr Fold, soeben im Rahmen des MWC in Barcelona angekündigt, sei das erste faltbare Smartphone der Marke im Buchformat, hält der Hersteller fest. Das Gerät bietet ein 6,6 Zoll grosses Aussendisplay; aufgeklappt erscheint ein 2K-LTPO-Innendisplay…

  • Sind regelmässige Passwortänderungen wirklich sinnvoll?

    2. Februar 2026 Jedes Jahr am 1. Februar findet der „Ändere dein Passwort“-Tag statt. Der Tipp ist jedoch ausgelutscht und kontraproduktiv. Es ist wieder „Ändere dein Passwort“-Tag am heutigen 1. Februar 2026! Haben Sie Ihre Passwörter schon alle geändert? Nein? Das geht auch in Ordnung! Denn regelmässige Passwortänderungen sind nicht mehr zeitgemäss. Ursprünglich hatte die Idee, wenigstens ein Mal im Jahr an die Passwort-Sicherheit zu erinnern und…

  • Kontaktloses Bezahlen im digitalen Alltag via NFC

    6. Februar 2026 Welche Daten werden übertragen und welche Vorteile hat NFC? Eine Einführung und Einschätzung der Nutzung sowie der Risiken vom BSI. Kontaktloses Bezahlen via Near Field Communication (NFC) hält Einzug in unserem digitalen Alltag. Dabei kann sowohl eine Giro- oder Kreditkarte als auch ein Smartphone (oder andere mobile Endgeräte Smart Watches und Tablets) zum Übertragen der Bezahldaten dienen. Um Bezahlvorgänge unkomplizierter, schneller und trotzdem sicher zu gestalten, gibt es…

  • Faltbares Smartphone – Google Pixel 10 Fold – ein Flop?

    29. Januar 2026 Lange Zeit waren mir die Falter im zugeklappten Zustand viel zu schmal und deutlich zu dick – als hätte man zwei Handys aufeinandergelegt. Auch das erste Google Pixel Fold (Test) machte mit seinem breiten Format und riesigen Display-Rändern auf mich einen extrem unhandlichen Eindruck.. Es hat ein paar Generationen gedauert, aber mittlerweile sind die meisten Falter trotz Display im Vollformat nicht viel dicker als…