DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2025-14847

High CISA KEV
Low Medium High Critical
7.5
CVSS Score
Published: Dec 19, 2025
Last Modified: Jan 13, 2026

Vulnerability Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
N
Availability
N

Severity Details

7.5
out of 10.0
High

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Key Information

Published Date
December 19, 2025

Related News Articles

Latest news and updates about CVE-2025-14847

MongoDB Vulnerability CVE-2025-14847: Active Exploitation Affects Over 87,000 Instances

A severe security vulnerability in MongoDB known as CVE-2025-14847 (CVSS score: 8.7) has been actively exploited worldwide, affecting over 87,000…
Read More

MongoDB Vulnerability CVE-2025-14847: A Global Cybersecurity Threat

Stay ahead of potential threats with MongoDB's most severe vulnerability CVE-2025-14847, affecting over 87,000 instances worldwide. Learn how to mitigate…
Read More