#CVE-2025-14847
Obligatory blog post describing the detection methodology I used.

blog.ecapuano.com/p/hunting-mo...
Hunting MongoBleed (CVE-2025-14847)
Detecting CVE-2025-14847 Exploitation with Velociraptor
blog.ecapuano.com
December 27, 2025 at 3:42 AM
How much longer are we going to give *end users* direct control over memory buffer sizes?

www.abstract.security/blog/critica...
Critical MongoDB Vulnerability: CVE-2025-14847 (MongoBleed)
CVE-2025-14847 (MongoBleed) is a critical MongoDB vulnerability enabling unauthenticated memory disclosure. Learn impact, affected versions, and detection steps.
www.abstract.security
December 28, 2025 at 11:27 PM
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds.

Somebody posted an exploit on Christmas Day, Merry Christmas!

doublepulsar.com/merry-christ...
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
doublepulsar.com
December 26, 2025 at 10:57 PM
A high-severity flaw known as MongoBleed (CVE-2025-14847) is currently being exploited in the wild. Wiz researchers have confirmed active exploitation.

Read More: www.security.land/mongobleed-a...

#SecurityLand #CyberSecurity #InfoSec #MongoDB #MongoBleed #DatabaseSecurity #Wiz #Shodan
MongoBleed CVE-2025-14847: Is Your MongoDB Exposed?
Dubbed "MongoBleed," CVE-2025-14847 allows unauthenticated attackers to exfiltrate sensitive data from MongoDB heap memory. With 87,000 instances exposed, active exploitation is now confirmed.
www.security.land
December 28, 2025 at 12:55 PM
Solid content (per usual) from @doublepulsar.com

Defenders might want to put eyes on this and scope for affected systems.

doublepulsar.com/merry-christ...
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
doublepulsar.com
December 26, 2025 at 7:04 PM
Meus sentimentos pra quem vai passar esses dias de recesso atualizando versão do mongodb #hugops

www.tenable.com/blog/cve-202...
MongoBleed CVE-2025-14847 exploited in the wild
MongoBleed CVE-2025-14847 exploited in the wild
www.tenable.com
December 29, 2025 at 8:42 PM
I have PR'd a new @velocidex.com Artifact to the Exchange to hunt for exploitation of #CVE-2025–14847.

As far as I know, this is the only defensive signature for this CVE that exists currently.

github.com/Velocidex/ve...
Create Linux.Detection.CVE202514847.MongoBleed.yaml by ecapuano · Pull Request #1161 · Velocidex/velociraptor-docs
Add Linux.Detection.CVE202514847.MongoBleed Artifact Summary This artifact detects evidence of CVE-2025-14847 (MongoBleed) exploitation on MongoDB servers by analyzing connection patterns in MongoD...
github.com
December 27, 2025 at 1:52 AM
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.
www.bleepingcomputer.com
December 28, 2025 at 8:38 PM
MongoBleed update: We added MongoDB CVE-2025-14847 tagging today that is version based. This results in 74,854 possibly unpatched versions (out of 78,725 exposed today). IP data on vulnerable instances shared in our Open MongoDB Report: www.shadowserver.org/what-we-do/n...
December 29, 2025 at 7:36 PM
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
thehackernews.com
December 29, 2025 at 8:10 AM
⚠️📢 MongoDB: Aktiv ausgenutzte Schwachstelle mit der Kennung CVE-2025-14847 erlaubt Offenlegung sensibler Daten.
Am 19.12.2025 veröffentlichte das Unternehmen ein Advisory zu einer Schwachstelle in seinem gleichnamigen NoSQL-Datenbankmanagementsystem.
Mehr Infos: https://www.bsi.bund.de/dok/1189714
Version 1.0: MongoDB - Aktiv ausgenutzte Schwachstelle erlaubt Offenlegung sensibler Daten
Am 19. Dezember 2025 veröffentlichte das Unternehmen MongoDB ein Advisory zu einer Schwachstelle in seinem gleichnamigen NoSQL-Datenbankmanagementsystem. Darin informierte der Hersteller über die Schwachstelle mit der Kennung CVE-2025-14847, welche nach dem Common Vulnerability Scoring System mit ...
www.bsi.bund.de
December 29, 2025 at 4:00 PM
MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)
MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)
cybersecuritynews.com
December 29, 2025 at 8:29 AM
MongoDB recently patched CVE-2025-14847, a vulnerability affecting multiple supported and legacy MongoDB Server versions. The flaw can be exploited remotely by unauthenticated attackers with low complexity, potentially leading to the exfiltration of sensitive data.

www.infoq.com/news/2026/01...
MongoBleed Vulnerability Allows Attackers to Read Data from MongoDB's Heap Memory
MongoDB recently patched CVE-2025-14847, a vulnerability affecting multiple supported and legacy MongoDB Server versions. According to the disclosure, the flaw can be exploited remotely by unauthentic...
www.infoq.com
January 15, 2026 at 12:17 PM
MongoDB爆出高危内存泄露漏洞CVE-2025-14847(代号MongoBleed),攻击者可通过特制压缩包远程读取服务器内存中的密钥、会话令牌等敏感信息。

影响版本:4.4.x至8.2.x全线版本

mp.weixin.qq.com/s/D647GdoQGx...

#数据库安全 #漏洞防护 #MongoDB #网络安全 #哪吒网络安全 #MongoBleed #CVE-2025-14847 #poc
January 10, 2026 at 5:44 PM
High-severity MongoDB flaw CVE-2025-14847 could lead to server takeover

MongoDB addressed a high-severity vulnerability that can be exploited to achieve remote code execution on vulnerable servers. MongoDB addressed a high-severity vulnerability, tracked as CVE-2025-14847 (CVSS s…
#hackernews #news
High-severity MongoDB flaw CVE-2025-14847 could lead to server takeover
MongoDB addressed a high-severity vulnerability that can be exploited to achieve remote code execution on vulnerable servers. MongoDB addressed a high-severity vulnerability, tracked as CVE-2025-14847 (CVSS score 8.7), an unauthenticated, remote attacker can exploit the issue to execute arbitrary code on vulnerable servers. “An client-side exploit of the Server’s zlib implementation can return uninitialized heap […]
securityaffairs.com
December 26, 2025 at 7:07 PM
I especially love this part:

"Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day."

...followed by...

"The exploit author has provided no details on how to detect exploitation in logs via products like.. Elastic."

Love that for us.
December 26, 2025 at 7:04 PM
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #MongoDB product:

CVE-2025-14847: remote unauthenticated memory reading #MongoBleed

search.onyphe.io/search?q=cat...
December 28, 2025 at 5:45 PM
🚨🚨🚨 PATCH YO' MONGODB - PUBLIC POC AVAILABLE 🚨🚨🚨

m.cje.io/4q2Bi1Y
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
m.cje.io
December 27, 2025 at 1:39 PM
MongoBleed (CVE-2025-14847) Information Leak Vulnerability Exploited in the Wild by Peled Eldan & Erez Hasson XM Cyber. Vulnerability is currently being exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities Catalog on December 29, 2025. cybersec.xmcyber.com/s/mongobleed...
January 29, 2026 at 3:15 PM
SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847
https://isc.sans.edu/podcastdetail/9750
December 28, 2025 at 5:10 AM