Home / CVE DB / CVE-2025-14847
Standard
Vulnerability Identifier

CVE-2025-14847

2025-12-19
Severity Assessment
7.5
HIGH
CVSS v3.x Score

CISA KEV Active Alert

Date Added
01 Jan 1970
Due Date
N/A
Required Action
Apply updates per vendor instructions.
Clinical Analysis (Description)

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Vector Sequencing

Attack Parameters

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Impact Consequences

Technical Impact

Unchanged
Scope
High
Confidentiality
None
Integrity
None
Availability
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Classification

CWE-CWE-130

Timeline

Time Line

PUBLICATION
19 Dec 2025
MODIFICATION
13 Jan 2026
Impact Statistics

Key Metrics

CVSS Score
7.5
HIGH
Articles
6
Published
Active Exploitation Confirmed
Remediation Protocol

Recommended Solution

No automatic solution found. Check vendor references.
Patch Library
No direct patch listed in database.
Associated Cyber Intelligence

Related News Articles

6 article(s) mentioning this vulnerability

Article #1

Critical MongoDB Flaw Allows Unauthenticated Memory Reading

A high-severity vulnerability in MongoDB (CVE-2025-14847) allows unauthenticated users to read uninitialized heap memory, posing a significant risk to data…

7
02 Jan 2026 vulnerability HIGH
Article #2
8

MongoDB Vulnerability CVE-2025-14847: Uninitialized Memory Access

A critical flaw in MongoDB allows unauthenticated users to read uninitialized heap memory. CVE-2025-14847 has a high CVSS score of…

02 Jan 2026 Vulnerability CRITICAL
Article #3

MongoDB Vulnerability CVE-2025-14847: A Global Cybersecurity Threat

Stay ahead of potential threats with MongoDB's most severe vulnerability CVE-2025-14847, affecting over 87,000 instances worldwide. Learn how to mitigate…

9
02 Jan 2026 vulnerability CRITICAL
Article #4
9

MongoDB Vulnerability CVE-2025-14847: Active Exploitation Affects Over 87,000 Instances

A severe security vulnerability in MongoDB known as CVE-2025-14847 (CVSS score: 8.7) has been actively exploited worldwide, affecting over 87,000…

02 Jan 2026 Vulnerability CRITICAL
Article #5

Une vulnérabilité critique dans MongoDB permet la lecture non authentifiée de la mémoire tampon

Une vulnérabilité critique dans MongoDB (CVE-2025-14847) permet la lecture non authentifiée de la mémoire tampon, posant un risque significatif pour…

7
02 Jan 2026 vulnérabilité HIGH
Article #6
9

Vulnérabilité MongoDB CVE-2025-14847 : Exploitation Active Affecte Plus de 87 000 Instances

Une vulnérabilité sévère dans MongoDB connue sous le nom de CVE-2025-14847 (score CVSS : 8.7) a été activement exploité à…

01 Jan 2026 Vulnérabilité CRITICAL
Recommended Actions for Administrators

Immediate Action Plan

1. Inventory

Identify all affected systems in your infrastructure.

2. Assessment

Assess exposure and criticality for your organization.

3. Mitigation

Apply patches or available workarounds.

4. Verification

Test and confirm effectiveness of applied measures.

⚠️ MAXIMUM PRIORITY - Immediate action required