logo

CVE-2025-14847 (MongoBleed): MongoDB Memory Leak Vulnerability Exploited in the Wild

ID: d7bf70cf-790f-5b67-818d-314665c481f6

STIX ID: report--d7bf70cf-790f-5b67-818d-314665c481f6

Feed Name: Tenable Blog

Threat Score
80/100

Date Published: 2025-12-29

Date Updated: 2026-05-01

Author: Scott Caveza

...
...

A memory-leak vulnerability in MongoDB's zlib decompression (CVE-2025-14847, "MongoBleed") can allow unauthenticated attackers to read uninitialized memory and potentially expose credentials, session tokens, and other sensitive data. A public proof-of-concept and reports of in-the-wild exploitation exist, and Censys identified roughly 87,000 potentially vulnerable internet-exposed instances; MongoDB has released patches and recommends disabling zlib or restricting access if immediate patching is not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.