MongoBleed (CVE-2025-14847) Exploits Unpatched MongoDB Servers
First seen 31 Dec 2025, 17:21 UTC
•
•37
Export
Article Content
Browse articles
CVE-2025-14847, known as MongoBleed, allows attackers to remotely leak memory from unpatched MongoDB servers using zlib compression without authentication. This critical vulnerability was disclosed shortly after Christmas 2025, affecting MongoDB Server deployments that utilize zlib network compression, with the U.S., China, and the EU among the most exploited regions.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms
Critical PostgreSQL Vulnerability Exposes Databases to Remote Code Execution
AWS Strands Agents Tools Exposed to Multiple CVEs in 23 Days
Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks
Critical MongoDB Vulnerability Allows Arbitrary Code Execution