Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-14847
MongoDB Inc. MongoDB Server — Zlib compressed protocol header length confusion may allow memory read
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H N N 8.7 .8322 99.7 YES
AFFECTED
Product Versions Fixed
MongoDB Server 8.2 – —
TIMELINE
Dec 17 Reserved by mongodb
Dec 19 Published (CNA: mongodb)
Dec 29 Added to CISA KEV, remediation due 2026-01-19
Description
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| December 17, 2025 | Reserved | Reserved by mongodb |
| December 19, 2025 | Published | Published (CNA: mongodb) |
| December 29, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2026-01-19 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| MongoDB Inc. | MongoDB Server | — | 8.2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-14847 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.