CVE-2025-14847 Details
Description
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
A vulnerability exists in MongoDB Server in the zlib compressed protocol headers, where mismatched length fields may lead to an unauthorized read of uninitialized heap memory. This issue affects multiple MongoDB Server versions across the 3.6 to 8.2 release series. The vulnerability arises from the server's handling of compressed messages, allowing a client to exploit the protocol and access sensitive memory areas without authentication.
Users are advised to upgrade to MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30. If an immediate upgrade is not possible, zlib compression can be disabled by starting the MongoDB server with a networkMessageCompressors or net.compression.compressors option that omits zlib, using alternatives like snappy, zstd, or disabling compression altogether.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847 | CISA-ADP | Third Party AdvisoryUS Government Resource |
| https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847 | CVE | Technical DescriptionThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server | CVE | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server | CVE | ExploitThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/29/21 | CVE | Mailing List |
| https://jira.mongodb.org/browse/SERVER-115508 | [email protected] | Issue TrackingPatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | Dec 29, 2025 | Jan 19, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mongodb mongodb | >= 3.6.0, < 4.4.30 >= 5.0.0, < 5.0.32 >= 6.0.0, < 6.0.27 >= 7.0.0, < 7.0.28 >= 8.0.0, < 8.0.17 >= 8.2.0, < 8.2.3 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 13, 2026 | Modified Analysis | [email protected] |
| Jan 12, 2026 | CVE Modified | CVE |
| Dec 31, 2025 | Initial Analysis | [email protected] |
| Dec 31, 2025 | CVE Modified | CVE |
| Dec 30, 2025 | CVE Modified | CISA-ADP |
| Dec 29, 2025 | CVE Modified | CVE |
| Dec 19, 2025 | New CVE Received | [email protected] |