CISA KEV · Known exploitedHigh

CVE-2025-14847

MongoDB MongoDB and MongoDB Server

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater...

CVSS
8.7
EPSS
83.0%
99.6% percentile
CISA KEV
Listed
Published
2025.12.19
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability83.0%
Technical severityCVSS 8.7

Vulnerability overview

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater...

Affected product and versions

Product
MongoDB MongoDB and MongoDB Server
Affected versions
8.2, 8.0, 7.0, 6.0, 5.0, 4.4, 4.2, 4.0, 3.6, >= 3.6.0 < 4.4.30, >= 5.0.0 < 5.0.32, >= 6.0.0 < 6.0.27, >= 7.0.0 < 7.0.28, >= 8.0.0 < 8.0.17, >= 8.2.0 < 8.2.3
Fixed versions
4.4.30, 5.0.32, 6.0.27, 7.0.28, 8.0.17, 8.2.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due date: 2026.01.19
  1. 1
    Identify

    Confirm that MongoDB MongoDB and MongoDB Server and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-130
KEV added
2025.12.29
Ransomware use
미확인
CVE-2025-14847 — MongoDB MongoDB and MongoDB Server | SECUFOCUS NOW