Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets
ID: e9683289-be5a-5fc9-a971-d22baa01e464
STIX ID: report--e9683289-be5a-5fc9-a971-d22baa01e464
Feed Name: The Cyber Express
Threat Score
A critical vulnerability in MongoDB's zlib compression handling (CVE-2025-14847, “MongoBleed”) enables unauthenticated remote out-of-bounds reads that can leak server memory — including credentials, session tokens, and stored data. Researchers observed active exploitation and published proof-of-concept code; MongoDB has released patches (8.0.4, 7.0.16, 6.0.19, 5.0.31) and defenders are advised to patch immediately or disable zlib compression as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
