Chameleon not vulnerable to MongoBleed - CVE-2025-14847

Incident Report for Chameleon

Resolved

Chameleon is not and was not not affected by the recently disclosed MongoDB vulnerability CVE-2025-14847 (aka. MongoBleed). It allows attackers to read arbitrary data from the database's heap memory. Chameleon's MongoDB instances are not publicly accessible and are also hosted with MongoDB Atlas which means they were patched before disclosure. We will, however, keep up to date on any developments from this incident
Posted Dec 29, 2025 - 08:00 EST