Percona Operator for MongoDB 1.21.2 has been released
Percona Operator for MongoDB 1.21.2 has been released on January 12, 2026.
Try it out using the Quickstart guide.
This release is the security update to address the security vulnerability CVE-2025-14847: CWE-130 in Percona Server for MongoDB about the use of zlib compression library. Attackers with network access to mongod or mongos can extract fragments of uninitialized server memory without authentication if zlib compression is enabled, and access sensitive data.
Percona Operator for MongoDB 1.21.2 includes the most recent versions of Percona Server for MongoDB with the fix. We recommend updating to Percona Operator for MongoDB 1.21.2 as soon as possible to ensure your deployments remain secure.
If an immediate update is not possible, you can disable zlib compression in Percona Server for MongoDB configuration or startup parameters.
Learn more about the security issue and remediation steps in Percona Blog: Urgent Security Update: Patching “Mongobleed” (CVE-2025-14847) in Percona Server for MongoDB.
Learn more about this release in Percona Operator for MongoDB 1.21.2 release notes.