logo

MongoBleed (CVE-2025-14847): What MongoDB Users Need to Know About This Memory Leak

ID: 9f593a4a-be91-598b-a309-deef895bf3da

STIX ID: report--9f593a4a-be91-598b-a309-deef895bf3da

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2025-12-29

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**MongoBleed (CVE-2025-14847)** is an unauthenticated memory-disclosure vulnerability in MongoDB servers that allows attackers to extract fragments of uninitialized heap memory via malformed zlib-compressed network messages, potentially exposing credentials, tokens, session identifiers and PII; it affects MongoDB versions from 3.6 through early 8.2.x, has a CVSS of 7.5, a public PoC and reports of active exploitation, and remediation includes upgrading to patched releases, disabling zlib compression, and restricting network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.