Critical severity9.1NVD Advisory· Published Nov 1, 2017· Updated May 13, 2026
CVE-2017-15535
CVE-2017-15535
Description
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/101689nvdThird Party AdvisoryVDB Entry
- jira.mongodb.org/browse/SERVER-31273nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.