ID: I202512291459
Status: idea
Tags: CVE, MongoDB, vulnerability
MongoBleed CVE-2025-14847
On Christmas there was a new vulnerability released called MongoBleed. Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client.
It is rated as a lever 8.7 or 7.5 depending on the version of MongoDB. Users that do not have their own database and instead use MongoDB Atlas are not affected because the reporter has already contacted the MongoDB team before making it public.
affected:
- affected fromĀ 8.2Ā beforeĀ 8.2.3Ā
- affected fromĀ 8.0Ā beforeĀ 8.0.17Ā
- affected fromĀ 7.0Ā beforeĀ 7.0.28Ā
- affected fromĀ 6.0Ā beforeĀ 6.0.27Ā
- affected fromĀ 5.0Ā beforeĀ 5.0.32Ā
- affected fromĀ 4.4Ā beforeĀ 4.4.30Ā
- affected atĀ 4.2Ā
- affected atĀ 4.0Ā
- affected atĀ 3.6
The CVE is named MongoBleed because it works the same way as the Heartbleed CVE from 2014. You can read more about Hearbleed on www.heartbleed.com.
References
- CVE.org
- NCSC
- National vulnerability DB
- Aikido
- mongobleed detector github script.