Skip to content
COOEY

EXPOSURES › CVE-2025-14847

CVE-2025-14847

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-14847 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

MongoDB exposed uninitialized heap memory through Zlib protocol headers

MongoDB and MongoDB Server failed to properly handle length parameter inconsistency in Zlib-compressed protocol headers, allowing unauthenticated clients to read uninitialized heap memory. This was actively exploited in the wild, posing a high risk to DIB organizations.

Shame score — Actively exploited in the wild with no indication of patching, leading to uninitialized memory reads.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
MongoDB Atlas for Government
MongoDB
Authorized