CVE-2025-14847HIGH 7.5CISA KEVEPSS p99.6%
CVE-2025-14847MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB / MongoDB and MongoDB Server
Description
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
Scoring
| CVSS 3.1 | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 83.01% probability of exploitation · percentile 99.6% · 2026-06-16T12:03:06Z |
| Published | 2025-12-19 |
| Last modified | 2026-01-13 |
CISA KEV entry
Added to KEV: 2025-12-29
Underlying weaknesses· 1
References
- https://jira.mongodb.org/browse/SERVER-115508
- http://www.openwall.com/lists/oss-security/2025/12/29/21
- https://www.smartkeyss.com/post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847
- https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server
- https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14847
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Handling of Length Parameter Inconsistencycwe-130 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerabilitykev-cve-2025-14847 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.