MongoBleed (CVE-2025-14847): What MongoDB Users Need to Know About This Memory Leak
ID: 9f593a4a-be91-598b-a309-deef895bf3da
STIX ID: report--9f593a4a-be91-598b-a309-deef895bf3da
Feed Name: SOCRadar Blog
**MongoBleed (CVE-2025-14847)** is an unauthenticated memory-disclosure vulnerability in MongoDB servers that allows attackers to extract fragments of uninitialized heap memory via malformed zlib-compressed network messages, potentially exposing credentials, tokens, session identifiers and PII; it affects MongoDB versions from 3.6 through early 8.2.x, has a CVSS of 7.5, a public PoC and reports of active exploitation, and remediation includes upgrading to patched releases, disabling zlib compression, and restricting network access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
