CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Dec 29, 2025
- US federal agencies must remediate it by Jan 19, 2026 (BOD 22-01)
- First attack observed 9 days after disclosure
- Confirmed by sensors, not only by reports
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 23, 2026 Sep 22, 2026 Jun 14, 2026 Apr 9, 2026 Mar 11, 2026 Jan 20, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAffected products
| Vendors | Product | Versions |
|---|---|---|
| mongodb | mongodb | < 4.4.30 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
