boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-14847

MongoDB Inc. MongoDB Server — Zlib compressed protocol header length confusion may allow memory read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .8322   99.7   YES
AFFECTED
  Product         Versions  Fixed
  MongoDB Server  8.2 –     —
TIMELINE
  Dec 17  Reserved by mongodb
  Dec 19  Published (CNA: mongodb)
  Dec 29  Added to CISA KEV, remediation due 2026-01-19
CWE-130 · CNA: mongodb · CVSS v4.0 · 6 references · KEV due January 19, 2026

Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
December 17, 2025ReservedReserved by mongodb
December 19, 2025PublishedPublished (CNA: mongodb)
December 29, 2025KEV ADDEDAdded to CISA KEV, remediation due 2026-01-19

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
MongoDB Inc.MongoDB Server—8.2—

Weaknesses

CWE-130

References (6)

Related

Authoritative record: CVE-2025-14847 at cve.org

Vendors: mongodb

Weaknesses: CWE-130

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-14847 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.