logo

MongoBleed (CVE-2025-14847): A Critical MongoDB Memory Leak Vulnerability Hidden for 8 Years

ID: 058f30b6-085f-5f62-9f70-fd381248a121

STIX ID: report--058f30b6-085f-5f62-9f70-fd381248a121

Feed Name: ASEC

Threat Score
80/100

Date Published: 2026-01-12

Date Updated: 2026-05-13

Author: ATCP

...
...

This report analyzes MongoBleed (CVE-2025-14847), a zlib-based OP_COMPRESSED decompression length-handling bug in MongoDB that can expose uninitialized heap memory to unauthenticated remote attackers; it explains the root cause, attack flow, why it remained undetected for years, documents evidence of active exploitation (CISA KEV listing and a suspected gaming service incident), and recommends immediate patching or mitigations such as disabling zlib compression and tightening network exposure and logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.