Vulnerability record · CVE-2025-14847 · published 19 December 2025
CVE-2025-14847: MongoDB Server heap memory disclosure via compressed protocol headers
Mongodb · Mongodb
Mismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Server. Because the flaw is reachable before authentication and affects a very wide range of server versions, any exposed MongoDB endpoint is a candidate target. The record does not state what data resides in the exposed heap region, so the sensitivity of leaked content cannot be confirmed from the facts given.
Description
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated network-reachable memory disclosure across a broad set of MongoDB versions, listed in CISA KEV with public exploit tooling and a very high EPSS score.
What it is
Mismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Server. Because the flaw is reachable before authentication and affects a very wide range of server versions, any exposed MongoDB endpoint is a candidate target. The record does not state what data resides in the exposed heap region, so the sensitivity of leaked content cannot be confirmed from the facts given.
Impact
An attacker gains read access to uninitialized heap memory from the server process, which may disclose fragments of other clients' data or internal server state. There is no evidence in the record of data modification or denial of service; the CVSS vector shows high confidentiality impact only.
Attack surface
Reached over the network through the MongoDB wire protocol when Zlib compression is negotiated, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any MongoDB Server instance accepting client connections with compression enabled is in scope.
Exploitation
CVE-2025-14847 was added to CISA KEV on 2025-12-29 with a remediation due date of 2026-01-19, and EPSS gives a 30-day probability of 0.83218 (99.66th percentile). Two third-party references are tagged as exploit and mitigation scripts, indicating public exploitation tooling exists; no ransomware campaign use is documented.
What to do
- Upgrade to a fixed release: 7.0.28, 8.0.17, 8.2.3, 6.0.27, 5.0.32, or 4.4.30 as applicable; note that 4.2.x, 4.0.x and 3.6.x have no fixed version listed and should be treated as end-of-life.
- If immediate patching is not possible, disable Zlib wire-protocol compression on clients and servers, or restrict network access to MongoDB listeners to trusted hosts only.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud-hosted MongoDB services, including discontinuing use where no mitigation is available.
- Inventory all MongoDB Server instances, including embedded and self-managed deployments, and confirm which versions fall in the affected ranges.
- Monitor vendor advisory SERVER-115508 for updated fixed versions covering the older 4.2, 4.0 and 3.6 branches.
Detection
- Alert on MongoDB connections negotiating Zlib compression from unexpected or untrusted source addresses.
- Hunt for repeated or malformed OP_COMPRESSED messages with inconsistent length fields in network or proxy logs.
- Review MongoDB server logs and host telemetry for anomalous connection patterns against exposed database ports.
- Track external exposure of MongoDB listeners and verify no instance is reachable from the public internet without a patch.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-14847 to the Known Exploited Vulnerabilities catalog on 29 December 2025 as "MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 January 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jira.mongodb.org/browse/SERVER-115508 | Issue TrackingPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/29/21 | Mailing List |
| https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847 | Technical DescriptionThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847 | Third Party AdvisoryUS Government Resource |
Track CVE-2025-14847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-14847), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.