Hacker News new | ask | show | jobs
MongoDB CVE CVE-2025-14847 – what K8s users should know? (armosec.io)
2 points by jkaftzan 170 days ago
1 comments

A newly disclosed MongoDB vulnerability, tracked as CVE-2025-14847 and informally referred to as MongoBleed, allows unauthenticated remote attackers to leak uninitialized memory from a MongoDB server. A public proof-of-concept exploit is already available, significantly increasing the risk for exposed MongoDB deployments.

This blog explains how the vulnerability works, what is required to exploit it, and how to identify exposure and detect exploitation attempts at runtime.