← Vulnerability feed

Vulnerability record · CVE-2025-14847 · published 19 December 2025

CVE-2025-14847: MongoDB Server heap memory disclosure via compressed protocol headers

Mongodb · Mongodb

Mismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Server. Because the flaw is reachable before authentication and affects a very wide range of server versions, any exposed MongoDB endpoint is a candidate target. The record does not state what data resides in the exposed heap region, so the sensitivity of leaked content cannot be confirmed from the facts given.

8.7 CVSS 4.0 High CISA KEV since 29 Dec 2025 EPSS 83% · top 0.3% CWE-130 · CWE-130
8.7CVSS 4.0 base score
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable memory disclosure across a broad set of MongoDB versions, listed in CISA KEV with public exploit tooling and a very high EPSS score.

What it is

Mismatched length fields in Zlib-compressed protocol headers let an unauthenticated client trigger a read of uninitialized heap memory in MongoDB Server. Because the flaw is reachable before authentication and affects a very wide range of server versions, any exposed MongoDB endpoint is a candidate target. The record does not state what data resides in the exposed heap region, so the sensitivity of leaked content cannot be confirmed from the facts given.

Impact

An attacker gains read access to uninitialized heap memory from the server process, which may disclose fragments of other clients' data or internal server state. There is no evidence in the record of data modification or denial of service; the CVSS vector shows high confidentiality impact only.

Attack surface

Reached over the network through the MongoDB wire protocol when Zlib compression is negotiated, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any MongoDB Server instance accepting client connections with compression enabled is in scope.

Exploitation

CVE-2025-14847 was added to CISA KEV on 2025-12-29 with a remediation due date of 2026-01-19, and EPSS gives a 30-day probability of 0.83218 (99.66th percentile). Two third-party references are tagged as exploit and mitigation scripts, indicating public exploitation tooling exists; no ransomware campaign use is documented.

What to do

  • Upgrade to a fixed release: 7.0.28, 8.0.17, 8.2.3, 6.0.27, 5.0.32, or 4.4.30 as applicable; note that 4.2.x, 4.0.x and 3.6.x have no fixed version listed and should be treated as end-of-life.
  • If immediate patching is not possible, disable Zlib wire-protocol compression on clients and servers, or restrict network access to MongoDB listeners to trusted hosts only.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud-hosted MongoDB services, including discontinuing use where no mitigation is available.
  • Inventory all MongoDB Server instances, including embedded and self-managed deployments, and confirm which versions fall in the affected ranges.
  • Monitor vendor advisory SERVER-115508 for updated fixed versions covering the older 4.2, 4.0 and 3.6 branches.

Detection

  • Alert on MongoDB connections negotiating Zlib compression from unexpected or untrusted source addresses.
  • Hunt for repeated or malformed OP_COMPRESSED messages with inconsistent length fields in network or proxy logs.
  • Review MongoDB server logs and host telemetry for anomalous connection patterns against exposed database ports.
  • Track external exposure of MongoDB listeners and verify no instance is reachable from the public internet without a patch.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-14847 to the Known Exploited Vulnerabilities catalog on 29 December 2025 as "MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 January 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-14847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-3085Mongodb vulnerabilityA MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…EPSS 0.27%9.8CVE-2024-8654Mongodb use of uninitialized resource vulnerabilityMongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…EPSS 0.37%9.8CVE-2024-1351Mongodb improper certificate validation vulnerabilityUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…EPSS 0.50%9.2CVE-2026-82067Mongodb vulnerabilityImproper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in …EPSS 0.51%9.2CVE-2026-13072Mongodb heap-based buffer overflow vulnerabilityWhen compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…EPSS 0.40%9.1CVE-2017-15535Mongodb vulnerabilityMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…EPSS 1.6%9.0CVE-2026-18691Mongodb vulnerabilityAn issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…EPSS 0.36%8.8CVE-2025-6706Mongodb use after free vulnerabilityAn authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not h…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2025-14847), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.