logo

MongoBleed defect swirls, stamping out hope of year-end respite

ID: 3e6fd00e-69bc-5382-8662-4796b0ed8587

STIX ID: report--3e6fd00e-69bc-5382-8662-4796b0ed8587

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

MongoBleed (CVE-2025-14847) is a high-severity memory-leak vulnerability in many default-configured MongoDB versions that can let unauthenticated actors leak server memory (potentially exposing credentials/tokens). Public proofs of concept and reports of active exploitation have appeared, tens of thousands of exposed instances were identified by scanning services, and the defect (CVSS 8.7) is notable for ease of exploitation at scale and limited forensic traces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.