Threat Brief: MongoDB Vulnerability (CVE-2025-14847)
ID: 32c43952-68f8-5011-adba-92b68085ae7d
STIX ID: report--32c43952-68f8-5011-adba-92b68085ae7d
Feed Name: Palo Alto Networks Unit 42
**MongoBleed (CVE-2025-14847)** — A critical, unauthenticated memory-disclosure vulnerability in MongoDB Server’s handling of zlib-compressed messages allows attackers with network access to leak heap memory (potentially exposing credentials, API keys, session tokens and PII); a public PoC and evidence of active exploitation exist, approximately 146,000 vulnerable instances were identified, CISA added the CVE to its KEV catalog, and the report provides mitigation, detection queries and product protection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
