• News/
  • https://www.theregister.com/2025/12/30/mongodb_vuln_exploited_cve_2025_14847/

An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

The Register
·
Brandon Vigliarolo
·
Published Dec 30, 2025
·
Updated

A high-severity MongoDB Server vulnerability, for which proofs of concept emerged over Christmas week, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency. It wouldn't be the holiday break without a potentially devastating security vulnerability popping up to crash the PTO party, and this one definitely fits the bill, with one expert calling it "basically Heartbleed for MongoDB." Yeah, it's that serious. Identified as CVE-2025-14847, this CVSS 8.7 vulnerability in the widely used open-source MongoDB Server stems from mismatched length fields in zlib-compressed protocol headers. If exploited with a malformed packet, an unauthenticated remote attacker can read uninitialized heap memory. As OX Security pointed out on Christmas Eve, that means an attacker could expose user info, passwords, API keys, and more. "Although the attacker might need to send a large amount of requests to gather the full database, and some data might be meaningless, the more time an attacker has the more information could be gathered," OX said. You know - time like they'd have over the Christmas holiday while the threat watchers are busy sucking down eggnog. Dubbed MongoBleed by the Elastic Security researcher who published a proof of concept on December 26, the vulnerability was actually identified back on December 15 and patched by the MongoDB crew shortly thereafter. It affects a wide range of MongoDB Server versions, with MongoDB urging affected users...

Read full article

Affected Software

1 affected component
MongoDB Server<exactly 6.0, <=up to 5.x, <=up to 4.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203