LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-14847: MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 29, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 19, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-14847 to its Known Exploited Vulnerabilities catalog on Dec 29, 2025, with a federal patch deadline of Jan 19, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an…

MongoDB Server is affected by an improper handling of length parameter inconsistency vulnerability in its Zlib compressed protocol headers. An unauthenticated client may be able to read uninitialized heap memory. The issue is tracked as CVE-2025-14847 and is classified under CWE-130.

How it works

The weakness is an inconsistency in how length parameters are handled within Zlib compressed protocol headers. An attacker can send crafted compressed data that causes the server to read beyond intended boundaries into uninitialized heap memory.

This occurs before authentication completes, allowing the read by an unauthenticated remote client. No further exploit mechanics are documented in the available summary.

Am I affected? How to find it in your systems

MongoDB Server instances commonly run as backend database services in application stacks. Inventory all deployments of MongoDB and MongoDB Server, including those hosted on-premises or in cloud environments.

How to remediate

Apply the vendor update referenced in the official advisory as the primary step. Follow all instructions supplied by MongoDB for the affected product versions.

If you can't patch immediately

Apply mitigations exactly as described in the vendor instructions. For cloud-hosted instances, follow any relevant BOD 22-01 guidance issued by CISA.

If your data may have been exposed

Memory disclosure vulnerabilities can contribute to later breaches when actively exploited. You can run a free exposure scan of your email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMongoDB · MongoDB and MongoDB Server
WeaknessCWE-130
Added to CISA KEVDec 29, 2025
Federal patch deadlineJan 19, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities