logo

Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

ID: 6306ecbf-f171-53a0-b85e-299692a4f5a3

STIX ID: report--6306ecbf-f171-53a0-b85e-299692a4f5a3

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-02

Date Updated: 2026-04-21

Author: Cyber Advisory

...
...

Mongobleed (CVE-2025-14847) is a high-severity pre-authentication zlib decompression flaw in MongoDB Server (affecting versions 3.6–8.2 through 8.2) that can return uninitialized heap memory to remote clients—potentially exposing database credentials, API keys, tokens, session data, and PII; public proof-of-concept code and active exploitation were reported, CISA added the issue to its KEV catalog, and mitigations include immediate patching (or disabling zlib), network segmentation, and rotating all potentially exposed secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.