MongoDB patched a high-severity information disclosure vulnerability, CVE-2025-14847 or MongoBleed, that allows a remote unauthenticated attacker to read sensitive heap memory from vulnerable servers. The flaw affects OP_COMPRESSED messages using zlib: by manipulating the BSON uncompressedSize field, an attacker can make MongoDB allocate an oversized buffer without validating the claimed length, which can cause the server to return uninitialized memory. Researchers said the leak can expose cleartext passwords, credentials, API keys, and other secrets, and can be amplified when a malformed BSON object omits a null terminator, causing MongoDB to continue parsing memory until a null byte is found and include leaked contents in an error response.
The vulnerability has been reported as actively exploited, and public proof-of-concept code is available. Affected releases include MongoDB Server 8.2 before 8.2.3, 8.0 before 8.0.17, 7.0 before 7.0.28, 6.0 before 6.0.27, 5.0 before 5.0.32, 4.4 before 4.4.30, and all versions of 4.2, 4.0, and 3.6. Defenders were urged to upgrade immediately, disable zlib request compression until patching is complete, restrict Internet exposure of TCP port 27017, review logs for exploitation attempts, and rotate passwords and cryptographic material that may have been exposed. Researchers also warned that internet-scale exposure could be significant, citing tens of thousands to more than 200,000 internet-accessible MongoDB instances identified by scanning services.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2025-14847 was being actively exploited and that public proof-of-concept exploit code was available. The notice also recommended immediate mitigation steps including upgrading, disabling zlib request compression, restricting Internet exposure, reviewing logs, and rotating potentially exposed secrets.
MongoDB Server released fixes for the high-severity information disclosure flaw CVE-2025-14847 (MongoBleed), which allows remote unauthenticated attackers to leak heap memory by abusing OP_COMPRESSED messages with a manipulated uncompressedSize field. Patched versions cited are 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30, while 4.2, 4.0, and 3.6 are affected without listed fixes.
Akamai published technical analysis explaining that MongoBleed stems from MongoDB trusting a forged BSON uncompressedSize value, causing oversized buffer allocation and possible disclosure of uninitialized heap memory. The write-up said malformed BSON without a null terminator can amplify leakage and noted large internet exposure estimates from Shodan and Censys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.