CVE-2025-14847: MongoBleed Information Disclosure Vulnerability Exploited in the Wild
ID: 71ceaa81-029e-502a-b163-895e82118b12
STIX ID: report--71ceaa81-029e-502a-b163-895e82118b12
Feed Name: Arctic Wolf
Threat Score
On 19 December 2025 MongoDB disclosed CVE-2025-14847 (“MongoBleed”), an unauthenticated high-severity memory-leak in zlib-based network compression that can expose credentials, API/cloud keys, tokens, and other sensitive data; public PoCs and active exploitation were observed with tens of thousands of potentially vulnerable instances internet-wide, and recommended mitigations are immediate upgrade to fixed MongoDB releases or disabling zlib (use zstd or Snappy).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
