Merry Christmas to everybody, except that dude who works for Elastic, who decided to drop an unauthenticated exploit for MongoDB on Christmas Day, that leaks memory and automates harvesting secrets (e.g. database passwords)

CVE-2025-14847 aka MongoBleed

Exp: github.com/joe-desimone/mongob

This one is incredibly widely internet facing and will very likely see mass exploitation and impactful incidents

Impacts every MongoDB version going back a decade.

Shodan dork: product:"MongoDB"

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://cyberplace.social/users/GossiTheDog/statuses/115786817774728155 on your instance and quote it. (Note that quoting is not supported in Mastodon.)