logo

CVE-2025-14847: MongoBleed Information Disclosure Vulnerability Exploited in the Wild

ID: 71ceaa81-029e-502a-b163-895e82118b12

STIX ID: report--71ceaa81-029e-502a-b163-895e82118b12

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

On 19 December 2025 MongoDB disclosed CVE-2025-14847 (“MongoBleed”), an unauthenticated high-severity memory-leak in zlib-based network compression that can expose credentials, API/cloud keys, tokens, and other sensitive data; public PoCs and active exploitation were observed with tens of thousands of potentially vulnerable instances internet-wide, and recommended mitigations are immediate upgrade to fixed MongoDB releases or disabling zlib (use zstd or Snappy).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.