Executive brief
MongoDB Server, a widely used database for storing and managing application data, is vulnerable to a security flaw that allows unauthorized users to view sensitive information. By sending specially crafted network requests, an attacker can read parts of the server's memory that they should not have access to. This could lead to the exposure of database credentials, session tokens, or actual customer data stored in the system. This vulnerability is currently being exploited in the wild, and organizations should update their database software immediately.
Technical details
A vulnerability exists in MongoDB Server's handling of Zlib compressed protocol headers (OP_COMPRESSED). The root cause is an improper handling of length parameter inconsistencies, where mismatched length fields in the header allow an unauthenticated remote attacker to trigger an out-of-bounds read of uninitialized heap memory. This can result in the disclosure of sensitive data residing in the server's memory space. The vulnerability affects multiple major versions ranging from 3.6 to 8.2. Patches have been released for all supported versions (e.g., 7.0.28, 8.0.17). This issue is tracked as CVE-2025-14847 and has been observed being exploited in the wild.
Affected products
- MongoDB MongoDB Server 3.6.0+, 4.0.0+, 4.2.0+, 4.4.0 < 4.4.30, 5.0.0 < 5.0.32, 6.0.0 < 6.0.27, 7.0.0 < 7.0.28, 8.0.0 < 8.0.17, 8.2.0 < 8.2.3
Timeline
- 2025-12-19: disclosed: Initial CVE record received from MongoDB
- 2025-12-29: advisory: Public disclosure and CISA KEV addition
- 2025-12-29: exploited: CISA confirmed active exploitation in the wild
- 2025-12-29: patched: Fixes available in updated versions (e.g., 7.0.28, 8.0.17)