<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — MongoDB</title><description>Actively exploited vulnerabilities affecting MongoDB products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/mongodb.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-14847 — MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-14847</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-14847</guid><description>MongoDB Server mishandles length parameters in Zlib-compressed protocol headers, allowing an unauthenticated remote client to read uninitialized heap memory. This is significant because no authentication is required to trigger the flaw, meaning any network-accessible MongoDB instance could leak sensitive memory contents to an attacker. Heap memory exposure can reveal credentials, query data, or internal state, potentially enabling further attacks or data breaches.</description><pubDate>Mon, 29 Dec 2025 00:00:00 GMT</pubDate><category>MongoDB</category><category>MongoDB and MongoDB Server</category></item></channel></rss>