US, Australia say ‘MongoBleed’ bug being exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-14847 | Unauthenticated Heap Memory Disclosure in MongoDB Server (MongoBleed) CVE-2025-14847 ('MongoBleed') is an improper handling of length parameter inconsistency (CWE-130) in MongoDB Server's processing of Zlib-compressed protocol headers, where mismatched length fields cause the server to return uninitialized heap memory. An unauthenticated remote client can trigger the leak by sending specially crafted compressed protocol messages to a vulnerable server, with no credentials, user interaction, or complex conditions required. The impact is confidentiality-only: an attacker can harvest fragments of the server's heap memory, which may contain sensitive in-memory data such as documents, credentials, or keys, reflected in the High confidentiality rating in the 8.7 CVSS 4.0 score. Virtually every MongoDB Server release from 3.6 through 8.2 is affected unless updated to the fixed patch levels (e.g., 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, 4.4.30), so the potentially exposed population is extremely large. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-29, is reported as actively exploited in the wild worldwide (including a joint US-Australia advisory), and carries a very high EPSS of 83.2%, making patching urgent. Do: Upgrade MongoDB Server immediately to the fixed release for your branch: 8.2.3+, 8.0.17+, 7.0.28+, 6.0.27+, 5.0.32+, or 4.4.30+; 3.6, 4.0, and 4.2 deployments are affected in all versions and should be moved to a patched release or retired per MongoDB guidance. Until patched, restrict network access to MongoDB to trusted clients and consider disabling Zlib network compression as an interim mitigation, and review logs for unauthenticated client connections. Because the flaw is on CISA's KEV catalog with active exploitation observed (including ransomware-adjacent tracking), apply mitigations per BOD 22-01 timelines or discontinue use of affected unpatched instances. | 8.7 | 83% | KEV PoC ×3 |
| masstens of thousands of MongoDB instances directly exposed to the internet, within millions of total deployments worldwide (estimate) |
Full article473 words · extracted from therecord.media · click to collapse
U.S. and Australian cyber agencies confirmed that hackers are exploiting a vulnerability that emerged over the Christmas holiday and is impacting data storage systems from the company MongoDB. The issue drew concern on December 25 when a prominent researcher published exploit code for CVE-2025-14847 — a vulnerability MongoDB announced on December 15 and patched on December 19. The Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its catalog of exploited vulnerabilities on Monday evening and ordered all federal civilian agencies to patch it by January 19. A CISA spokesperson declined to answer further questions about what U.S. agencies are doing to protect those who may be impacted. Australia’s Cyber Security Centre said in an advisory that it “is aware of active global exploitation of this vulnerability.” The vulnerability impacts a range of versions of MongoDB’s database management system. The bug was dubbed “MongoBleed” in reference to several previous vulnerabilities, including the CitrixBleed bug. Cybersecurity researcher Eric Capuano said the exploit “works by establishing many rapid connections to the MongoDB server — we’re talking tens of thousands per minute.” “Each connection probes for memory leaks, and the attacker aggregates the leaked data to reconstruct sensitive information,” he added. Douglas McKee, director of vulnerability intelligence at the cybersecurity firm Rapid7, told Recorded Future News the vulnerability affects thousands of internet-exposed MongoDB deployments by enabling access paths that bypass authentication controls under specific conditions. Cybersecurity experts at several organizations warned about the level of exposure related to the bug. The cyber company Wiz found that 42% of cloud environments have at least one instance of a version of MongoDB vulnerable to CVE-2025-14847 and experts at the company have confirmed “many internet-facing instances as exploitable.” Censys reported observing about 87,000 potentially vulnerable instances worldwide and the Shadowserver Foundation put the figure at 74,854. Rapid7’s McKee said similar large-scale exposure, combined with trivial access paths, has historically led to rapid, opportunistic abuse. “The issue highlights how exposure and access control failures can create material risk, even in the absence of a traditional exploit chain,” he said. “Based on historical patterns with similar MongoDB exposure issues, the most likely abuse would come from opportunistic actors conducting broad internet scanning rather than targeted or nation-state campaigns.” He added that MongoDB is used across the spectrum, from small startups and software-as-a-service providers to large enterprises and government environments. Cybersecurity expert Kevin Beaumont validated the exploit code over the weekend and said it allowed anyone to steal database passwords, AWS secret keys and more.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/us-australia-bug-exploitation