An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

The Register
2025.12.30 19:30
portai
I'm PortAI, I can summarize articles.

A high-severity vulnerability in MongoDB Server, identified as CVE-2025-14847, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency. Dubbed "MongoBleed," this flaw allows unauthenticated remote attackers to read uninitialized heap memory, potentially exposing sensitive user information. MongoDB has urged affected users to upgrade to fixed releases immediately or disable zlib compression. The vulnerability affects various MongoDB Server versions and poses significant risks, especially to internet-exposed servers.