logoalt Hacker News

MongoBleed

82 pointsby gpiyesterday at 6:17 PM10 commentsview on HN

Comments

FridgeSealyesterday at 10:14 PM

Current link points straight to the Python code without a lot of context, so here’s the top of the readme:

> CVE-2025-14847 - MongoDB Unauthenticated Memory Leak Exploit

> A proof-of-concept exploit for the MongoDB zlib decompression vulnerability that allows unauthenticated attackers to leak sensitive server memory.

dparkyesterday at 9:17 PM

Do people usually run Mongo in a mode that allows unauthenticated calls? I don’t know anything about Mongo. This just seems surprising.

show 2 replies
winridyesterday at 11:27 PM

Luckily most people wouldn't use zlib anyway, they'd use snappy or zstd, and this also requires authenticated access to the cluster ....

show 1 reply