PT-2025-52440 · Mongodb · Mongodb Server +1

Alan Coopersmith

·

Published

2025-12-19

·

Updated

2026-01-26

·

CVE-2025-14847

CVSS v4.0
8.7
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MongoDB versions 3.6 through 8.2.3 MongoDB Server versions 4.0 through 4.4.30 MongoDB Server versions 5.0 through 5.0.32 MongoDB Server versions 6.0 through 6.0.27 MongoDB Server versions 7.0 through 7.0.28 MongoDB Server versions 8.0 through 8.0.17 MongoDB Server versions 8.2 through 8.2.3
Description MongoDB is affected by a critical vulnerability (CVE-2025-14847), dubbed "MongoBleed," which allows unauthenticated remote attackers to read uninitialized heap memory. This is due to improper handling of length parameter inconsistency in Zlib compressed protocol headers. The vulnerability allows attackers to extract sensitive information, including credentials, API keys, and session tokens, without authentication. This flaw is actively being exploited in the wild, with over 87,000 instances potentially exposed globally. A public proof-of-concept exploit is available, simplifying exploitation. The vulnerability is similar in severity to the Heartbleed vulnerability.
Recommendations MongoDB versions prior to 3.6 are not affected. Upgrade to MongoDB version 8.2.3 or later. Upgrade to MongoDB Server version 4.4.30 or later. Upgrade to MongoDB Server version 5.0.32 or later. Upgrade to MongoDB Server version 6.0.27 or later. Upgrade to MongoDB Server version 7.0.28 or later. Upgrade to MongoDB Server version 8.0.17 or later. If an immediate upgrade is not possible, disable zlib compression. Restrict network access to MongoDB servers. Monitor for unusual activity and potential exploitation attempts. Rotate any potentially compromised credentials.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-16225
BIT-MONGODB-2025-14847
CVE-2025-14847

Affected Products

Mongodb Server
Mongodb