US and Australian cybersecurity agencies warned that MongoBleed (CVE-2025-14847) in MongoDB is being actively exploited, describing an unauthenticated memory disclosure issue that can leak heap data from exposed servers. Public reporting and advisory material indicate the flaw is tied to zlib decompression behavior and can expose sensitive information from MongoDB process memory, raising the risk of credential theft and follow-on compromise where internet-accessible instances are affected.
The warning was followed by a rapid surge of public GitHub repositories publishing proof-of-concept exploits, scanners, detection scripts, and lab environments for CVE-2025-14847. These tools advertise capabilities including external and container-based scanning, memory extraction, credential parsing, CIDR and batch targeting, and exploitation detection, lowering the barrier for both defenders validating exposure and attackers seeking vulnerable MongoDB deployments.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
An additional GitHub repository for CVE-2025-14847 exploitation was published, showing the vulnerability continued to attract public exploit development months after initial disclosure and warnings.
A more feature-rich GitHub toolkit for CVE-2025-14847 was published, advertising scanning, exploitation, memory extraction, credential parsing, CIDR or batch scanning, and Nuclei templates. This marked a further maturation of public tooling around MongoBleed.
New GitHub projects published a MongoBleed proof-of-concept exploit and a dedicated detection script for exploitation. These releases provided both offensive validation and defender-oriented detection capability.
A GitHub repository specifically describing CVE-2025-14847 as an unauthenticated MongoDB memory-leak exploit was published, adding to the growing set of public exploit implementations.
Multiple additional GitHub repositories for CVE-2025-14847 were published, including discovery and detection tooling as well as exploit-focused projects. This broadened public availability of offensive and defensive tooling around MongoBleed.
Government-linked reporting and an ACSC advisory warned that the MongoDB vulnerability CVE-2025-14847, dubbed MongoBleed, was under active exploitation. The advisory framed the issue as a MongoDB server memory leak requiring defensive attention.
Another GitHub repository for CVE-2025-14847 / MongoBleed was published, showing continued spread of public exploit material shortly after the initial code appeared.
A GitHub repository containing MongoBleed exploit code for CVE-2025-14847 was published, indicating public weaponization of the MongoDB memory leak issue. Another GitHub-hosted mongobleed.py exploit file also appeared the same day.
A further GitHub exploit project for CVE-2025-14847 was published, describing a Python script to leak sensitive MongoDB heap memory and analyze responses for newly disclosed data.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
14 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.