Critical 'MongoBleed' Bug Under Active Attack, Patch Now
ID: bff76377-0e69-50d0-9b3a-f28b299aa9cd
STIX ID: report--bff76377-0e69-50d0-9b3a-f28b299aa9cd
Feed Name: Dark Reading
A critical unauthenticated memory-leak vulnerability in MongoDB (CVE-2025-14847, dubbed "MongoBleed") is being actively exploited to extract cleartext credentials, tokens, and customer data from server RAM when Zlib compression is enabled; a public PoC and a user-friendly GUI exploitation tool emerged within days of disclosure, Rapid7 validated the PoC and urged immediate remediation and credential rotation, and MongoDB published patched versions and guidance to disable Zlib if immediate upgrade is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
