CVE-2025-14847

High7.5Published on December 19, 2025

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Dec 29, 2025
  • US federal agencies must remediate it by Jan 19, 2026 (BOD 22-01)
  • First attack observed 9 days after disclosure
  • Confirmed by sensors, not only by reports

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 23, 2026 Sep 22, 2026 Jun 14, 2026 Apr 9, 2026 Mar 11, 2026 Jan 20, 2026

CVSS score7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)CWE-130
Vendorsmongodb

Affected products

VendorsProductVersions
mongodbmongodb< 4.4.30

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database