More

    Thousands of servers exposed as MongoBleed vulnerability exploited



    • MongoBleed (CVE-2025-14847) leaks sensitive data via uninitialized heap memory exploitation
    • Roughly 87,000 exposed MongoDB instances vulnerable; most located in U.S., China, and Germany
    • Patch released December 19; MongoDB Atlas auto-patched, no confirmed in-the-wild abuse yet

    MongoBleed, a high-severity vulnerability plaguing multiple versions of MongoDB, can now easily be exploited since a proof-of-concept (PoC) is now available on the web.

    Earlier this week, security researcher Joe Desimone published code that exploits a “read of uninitialized heap memory” vulnerability tracked as CVE-2025-14847. This vulnerability, rated 8.7/10 (high), stems from “mismatched length fields in Zlib compressed protocol headers”.


    https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1920-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img