An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit
ID: 11c347db-ed70-5da2-9a44-7c1ec3c19c59
STIX ID: report--11c347db-ed70-5da2-9a44-7c1ec3c19c59
Feed Name: The Register (Security)
Threat Score
A high-severity zlib decompression vulnerability in MongoDB Server (CVE-2025-14847, "MongoBleed", CVSS 8.7) allows unauthenticated remote attackers to read uninitialized heap memory and potentially exfiltrate sensitive data. Proof-of-concept code was published, the issue is being actively exploited according to CISA, and MongoDB has released patches while advising users to upgrade or disable zlib compression if they cannot patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
