MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk
ID: e10f0b18-3897-5695-8ba8-2eb801639b41
STIX ID: report--e10f0b18-3897-5695-8ba8-2eb801639b41
Feed Name: cybersecurityNews.com
MongoBleed (CVE-2025-14847) is a critical pre-authentication information-leak in MongoDB's zlib-based decompression that returns uninitialized heap memory to unauthenticated clients, enabling remote exfiltration of sensitive data and credentials; a public PoC appeared on 2025-12-26 and active exploitation against internet-exposed instances has been reported, with tens of thousands of potentially vulnerable servers and multiple affected MongoDB series (some without available fixes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
