MongoBleed (CVE-2025-14847) Exploits Unpatched MongoDB Servers
First seen 31 Dec 2025, 17:21 UTC
•
•100% similarity
•37
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after Christmas 2025, affecting MongoDB Server deployments that utilize zlib network compression, with the U.S., China, and the EU among the most exploited regions.
ThreatCluster AI