CVE-2025-14847
MongoDB and MongoDB Server: Improper Handling of Length Parameter Inconsistency
As of , CVE-2025-14847 in MongoDB and MongoDB Server is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 29 December 2025
- US federal deadline
- 19 January 202621 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.83Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: jira.mongodb.orgLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
- jira.mongodb.orgThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used…
What the flaw is
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
CISA's description
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
The CVE record's description, from mongodb
- CVE published
- 19 December 2025
- Assigned by
- mongodb
- CVSS
- 8.7 High (CVSS 4.0, from the CNA)
- CWE-130
- Improper Handling of Length Parameter Inconsistency
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleedauxiliary module, rank normal
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org