logo

Kudelski Security Research Center

ID: edfac103-aa09-5c8b-a90f-522bd3dc1f8c

STIX ID: report--edfac103-aa09-5c8b-a90f-522bd3dc1f8c

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2025-12-29

Date Updated: 2026-07-22

...
...

CVE-2025-14847 (MongoBleed) is a high-severity pre-auth memory disclosure in MongoDB's zlib-compressed network handling that can return uninitialized heap memory to unauthenticated remote attackers, exposing database credentials, cloud keys, API tokens, and other sensitive data; a public exploit has been released and many self-hosted versions across multiple major releases are affected. The advisory lists affected versions, detection indicators (large connection volumes and unexpected leakage), immediate mitigations (patching to fixed versions, disabling zlib, restricting network exposure, enforcing TLS/authentication), and recommends inventory, prioritisation, and secrets rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.