
Threat Talks · 2026-02-17 · 14 min
Imagine your memory just became the attack surface. That’s MongoBleed. Or as others know it: CVE-2025-14847 . No passwords to crack, no complex exploit chain. Just normal protocol behavior, repeated at scale. Each request leaks a little more MongoDB memory until something valuable shows up, even in environments that already follow network segmentation best practices. Rob Maas (Field CTO, ON2IT) hosts Luca Cipriano (CTI & Red Team Program Lead) to dissect MongoBleed , an unauthenticated memory leak vulnerability in MongoDB, in this episode of Threat Talks . They break down how MongoBleed exploits MongoDB’s wire protocol before authentication and why repetition matters more than a single request. MongoDB is everywhere: cloud platforms, scalable applications, and data-heavy environments where availability matters more than friction. If MongoDB is part of your environment, or you want to understand how this vulnerability is exploited in practice, the full breakdown is worth your time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.