Infoq
MongoBleed Vulnerability Exposes MongoDB Data to Attackers
First seen 10 Jan 2026, 10:51 UTC
•
•52.9
Export
Article Content
Browse articles
MongoDB has patched CVE-2025-14847, a vulnerability that affects multiple versions of MongoDB Server. The flaw allows unauthenticated attackers to remotely exploit the vulnerability with low complexity, potentially leading to the exfiltration of sensitive data and credentials. The vulnerability has been dubbed 'MongoBleed' in reference to the infamous Heartbleed bug.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical Ruflo Vulnerability Allows Full Control of AI Agent Platforms
Critical PostgreSQL Vulnerability Exposes Databases to Remote Code Execution
AWS Strands Agents Tools Exposed to Multiple CVEs in 23 Days
Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Critical Vulnerability in free5GC Exposes 5G Core Network to Attacks
Critical MongoDB Vulnerability Allows Arbitrary Code Execution