Exploited Vulnerabilities Daily
🌐 English

Home › MongoDB

CVE-2025-14847: MongoDB MongoDB and MongoDB Server

EPSS83.2%No. 586 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV2
Same product1
FieldValue
VendorMongoDB
ProductMongoDB and MongoDB Server
NameMongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
Added to KEV2025-12-29
US federal due date2026-01-19
Ransomware useUnknown
CWECWE-130

CISA description

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.

NVD — CVE-2025-14847

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A MongoDB MongoDB and MongoDB Server vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-29.