CVE-2025-14847
CISA KEV Active Alert
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
Attack Parameters
Technical Impact
Time Line
Key Metrics
Recommended Solution
Related News Articles
6 article(s) mentioning this vulnerability
Critical MongoDB Flaw Allows Unauthenticated Memory Reading
A high-severity vulnerability in MongoDB (CVE-2025-14847) allows unauthenticated users to read uninitialized heap memory, posing a significant risk to data…
MongoDB Vulnerability CVE-2025-14847: Uninitialized Memory Access
A critical flaw in MongoDB allows unauthenticated users to read uninitialized heap memory. CVE-2025-14847 has a high CVSS score of…
MongoDB Vulnerability CVE-2025-14847: A Global Cybersecurity Threat
Stay ahead of potential threats with MongoDB's most severe vulnerability CVE-2025-14847, affecting over 87,000 instances worldwide. Learn how to mitigate…
MongoDB Vulnerability CVE-2025-14847: Active Exploitation Affects Over 87,000 Instances
A severe security vulnerability in MongoDB known as CVE-2025-14847 (CVSS score: 8.7) has been actively exploited worldwide, affecting over 87,000…
Une vulnérabilité critique dans MongoDB permet la lecture non authentifiée de la mémoire tampon
Une vulnérabilité critique dans MongoDB (CVE-2025-14847) permet la lecture non authentifiée de la mémoire tampon, posant un risque significatif pour…
Vulnérabilité MongoDB CVE-2025-14847 : Exploitation Active Affecte Plus de 87 000 Instances
Une vulnérabilité sévère dans MongoDB connue sous le nom de CVE-2025-14847 (score CVSS : 8.7) a été activement exploité à…
Immediate Action Plan
1. Inventory
Identify all affected systems in your infrastructure.
2. Assessment
Assess exposure and criticality for your organization.
3. Mitigation
Apply patches or available workarounds.
4. Verification
Test and confirm effectiveness of applied measures.
⚠️ MAXIMUM PRIORITY - Immediate action required
