Security advisories warned of two severe database software vulnerabilities with immediate internet-facing risk. In MongoDB, an unauthenticated network attacker can trigger an information disclosure flaw—described in some reporting as MongoBleed—to make a vulnerable server return sensitive data such as credentials, secrets, and personal information. The issue affects MongoDB releases dating back to about 2017 and stems from insufficient validation in the zlib implementation, which can leak uninitialized heap memory allocated to MongoDB. Working exploitation methods are known, and defenders were told to watch for large volumes of malformed or compressed requests, decompression or memory-handling errors, and repeated unauthenticated connections. Patches are available in versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30, while end-of-life branches remain unpatched.
A separate advisory disclosed a critical Redis vulnerability affecting 8.2.1 and earlier when Lua scripting is enabled, which is the default configuration. The flaw is a use-after-free condition that can be triggered by a specially crafted Lua script and may allow remote arbitrary code execution, giving an attacker full control of the host running Redis. Officials urged immediate upgrades because the vulnerability is publicly known and exploitation could begin within hours, and they advised organizations to inspect any previously exposed Redis environments for signs of compromise. Fixed versions were listed as 6.2.20, 7.2.11, 7.4.6, 8.0.4, and 8.2.2, alongside renewed guidance that Redis instances should not be exposed directly to the public internet.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Redis published fixed versions 6.2.20, 7.2.11, 7.4.6, 8.0.4, and 8.2.2 for the Lua scripting vulnerability. Guidance also reiterated that Redis instances should not be exposed directly to the public internet and that previously exposed systems should be checked for compromise.
A critical use-after-free vulnerability in Redis affecting version 8.2.1 and earlier was disclosed, impacting deployments with Lua scripting enabled by default. The flaw can potentially allow remote arbitrary code execution over the network, and defenders were warned that exploitation could begin within hours.
MongoDB released patched versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30 to address the information disclosure flaw, while end-of-life versions remain without fixes. Finland's NCSC published an alert describing exploitation indicators such as malformed or zlib-compressed requests and repeated unauthenticated connections.
A MongoDB vulnerability caused by insufficient validation in zlib can let an unauthenticated network attacker retrieve sensitive data such as credentials, secrets, and personal data from vulnerable servers. The issue affects all MongoDB versions released since approximately 2017, with working exploitation methods reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.