Skip to content

87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online

Cybersecuritynews Guru Baran December 28, 2025

A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score of 7.5. The vulnerability resides in the MongoDB Server’s zlib message decompression implementation. According to […]

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (2)