PT-2025-52440 · Mongodb · Mongodb Server +1

Alan Coopersmith

·

Published

2025-12-19

·

Updated

2026-01-14

·

CVE-2025-14847

CVSS v4.0
8.7
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MongoDB versions 3.6 through 8.2.3 MongoDB versions 8.0.0 through 8.0.16 MongoDB versions 7.0.0 through 7.0.28 MongoDB versions 6.0.0 through 6.0.27 MongoDB versions 5.0.0 through 5.0.32 MongoDB versions 4.4.0 through 4.4.30
Description MongoDB is affected by a critical vulnerability (CVE-2025-14847), dubbed "MongoBleed," stemming from improper handling of length parameter inconsistency in Zlib compressed protocol headers. This allows an unauthenticated attacker to read uninitialized heap memory, potentially exposing sensitive information such as credentials, API keys, and session tokens. The vulnerability is actively being exploited in the wild, with over 87,000 instances potentially exposed globally. A public proof-of-concept (PoC) exploit is available, simplifying exploitation. The issue affects all MongoDB Server versions from 3.6 through 8.2.2, and is particularly dangerous for internet-exposed instances. The vulnerability is similar in nature to the Heartbleed bug.
Recommendations MongoDB versions 3.6 through 8.2.3: Upgrade to a patched version (8.2.3 or later). MongoDB versions 8.0.0 through 8.0.16: Upgrade to version 8.0.17 or later. MongoDB versions 7.0.0 through 7.0.28: Upgrade to version 7.0.28 or later. MongoDB versions 6.0.0 through 6.0.27: Upgrade to version 6.0.27 or later. MongoDB versions 5.0.0 through 5.0.32: Upgrade to version 5.0.32 or later. MongoDB versions 4.4.0 through 4.4.30: Upgrade to version 4.4.30 or later. If an immediate upgrade is not possible, disable zlib compression on the MongoDB server. Restrict network access to MongoDB instances to prevent unauthorized access. Monitor logs for unusual activity and potential exploitation attempts.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-16225
BIT-MONGODB-2025-14847
CVE-2025-14847

Affected Products

Mongodb Server
Mongodb