Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-115508 | Issue Tracking Patch Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/29/21 | Mailing List |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server | Exploit Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
31 Dec 2025, 17:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:* cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
|
| First Time |
Mongodb
Mongodb mongodb |
|
| References | () https://jira.mongodb.org/browse/SERVER-115508 - Issue Tracking, Patch, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/12/29/21 - Mailing List | |
| References | () https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server - Exploit, Third Party Advisory | |
| References | () https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server - Exploit, Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847 - Third Party Advisory, US Government Resource |
31 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Dec 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Dec 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-19 11:15
Updated : 2025-12-31 17:32
NVD link : CVE-2025-14847
Mitre link : CVE-2025-14847
CVE.ORG link : CVE-2025-14847
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-130
Improper Handling of Length Parameter Inconsistency
