A critical unauthenticated vulnerability (CVE-2025-14847) has been discovered in MongoDB Server, specifically related to the handling of zlib-compressed network traffic. This flaw allows remote attackers with network access to a MongoDB instance configured with compression enabled to trigger the server into returning uninitialized heap memory in its responses. The leaked memory may contain sensitive data, including fragments of previously processed information, internal state, or confidential values, and no authentication is required to exploit this issue.
The vulnerability affects a wide range of MongoDB versions, including 3.6.x through 8.2.x, with patches available in versions 4.4.30, 5.0.32, 6.0.27, 7.0.28, 8.0.17, and 8.2.3. The root cause lies in the way MongoDB processes malformed zlib-compressed frames, leading to a length mismatch during decompression and the inadvertent inclusion of uninitialized memory in server responses. Given MongoDB's prevalence in cloud environments and its frequent exposure to the internet, this vulnerability poses a significant risk to organizations relying on the database for sensitive data storage and application backends.

See affected versions and whether adversaries are exploiting it.
12 events from the most recent confirmed update back to the earliest known activity.
By early January, researchers reported the emergence of a GUI-based exploitation tool for MongoBleed, reducing the technical skill needed to abuse the flaw. The development suggested continued commoditization of exploitation after the initial PoC release.
Rapid7 updated its Metasploit support for CVE-2025-14847 with a CHECK action, compression pre-flight checks, improved leak extraction, and JSON export. The enhancements enabled faster and more automated assessment of MongoDB targets.
Multiple reports claimed MongoBleed was used against Ubisoft infrastructure tied to Rainbow Six Siege, causing manipulation of game servers and in-game assets. The claim was presented as an early high-profile victim example, though some reporting described it as unverified.
A Metasploit auxiliary scanner module for CVE-2025-14847 was published, further lowering the barrier to test and identify vulnerable MongoDB servers. The release added another widely used offensive and defensive tool for validating exposure.
Government cyber agencies in the United States and Australia publicly warned that MongoBleed was being exploited globally. Their statements reinforced that exploitation was opportunistic and widespread rather than limited to isolated incidents.
CISA added MongoDB CVE-2025-14847 to its Known Exploited Vulnerabilities catalog because of evidence of active exploitation. The agency required U.S. federal civilian agencies to remediate the issue by the published deadline and urged all organizations to prioritize patching.
Open-source detector tools and artifacts were published to help organizations identify signs of MongoBleed exploitation in MongoDB logs. These tools focused on suspicious pre-authentication connection patterns and malformed compressed traffic associated with the exploit.
Security vendors and media began reporting that CVE-2025-14847 was being actively exploited against exposed MongoDB servers shortly after PoC publication. Reports said attackers were harvesting sensitive in-memory data such as credentials, API keys, and tokens from vulnerable systems.
Internet-wide exposure analysis reported that more than 87,000 publicly reachable MongoDB instances appeared potentially vulnerable to MongoBleed. The estimate highlighted the large attack surface and urgency of patching exposed self-managed deployments.
Researchers and tool authors released detection resources for CVE-2025-14847, including a Nuclei template and log-based hunting guidance to identify vulnerable or exploited MongoDB servers. These technical details expanded defenders' ability to scan for exposure and investigate compromise.
A public proof-of-concept exploit for CVE-2025-14847, later dubbed MongoBleed, was published on GitHub, making exploitation easier for attackers and defenders to validate exposure. Multiple later reports cite the PoC release as a key turning point in risk escalation.
MongoDB disclosed CVE-2025-14847, a pre-authentication zlib-related memory disclosure flaw in MongoDB Server, and released fixed versions for supported branches. The company advised customers to upgrade immediately or disable zlib compression as a temporary mitigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
44 references tracked. Mallory keeps watching after this page renders.
hackthebox.com
Open sourceblog.alphahunt.io
Open sourcehorizon3.ai
Open sourcerescana.com
Open sourcerunzero.com
Open sourcebleepingcomputer.com
Open sourceupwind.io
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.