CVE-2025-14847: MongoBleed Information Disclosure Vulnerability Exploited in the Wild
ID: 9ab561f0-842e-5f44-868b-9475dbd88d5b
STIX ID: report--9ab561f0-842e-5f44-868b-9475dbd88d5b
Feed Name: Arctic Wolf
**Executive Summary:** On December 19, 2025 MongoDB disclosed CVE-2025-14847 ("MongoBleed"), a critical zlib compression flaw that can cause unauthenticated remote requests to exfiltrate sensitive memory (passwords, API/cloud keys, session tokens, etc.); public PoC code and evidence of active exploitation against tens of thousands of exposed instances have been observed, and vendors recommend immediate upgrade to patched versions or disabling zlib compression (use zstd/Snappy or disabled) as a workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
