ThreatCluster

MongoBleed (CVE-2025-14847) Exploits Unpatched MongoDB Servers

First seen 31 Dec 2025, 17:21 UTC Securityaffairs.CoSecurityaffairs 37

Article Content

Browse articles
ThreatCluster

CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after Christmas 2025, affecting MongoDB Server deployments that utilize zlib network compression, with the U.S., China, and the EU among the most exploited regions.

Ask AI about this cluster