EXPOSURES › CVE-2025-14847
CVE-2025-14847
HIGH ⌖ ON CISA KEV · EXPLOITEDMongoDB exposed uninitialized heap memory through Zlib protocol headers
MongoDB and MongoDB Server failed to properly handle length parameter inconsistency in Zlib-compressed protocol headers, allowing unauthenticated clients to read uninitialized heap memory. This was actively exploited in the wild, posing a high risk to DIB organizations.
Shame score — Actively exploited in the wild with no indication of patching, leading to uninitialized memory reads.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
| PRODUCT | STATUS |
|---|---|
| MongoDB Atlas for Government MongoDB |
Authorized |