CVE-2025-14847
MongoDB Server: unauthenticated heap memory read through zlib-compressed message headers (MongoBleed)
Technology
MongoDB
CVSS Score
7.5 / 10.0
Affected Versions
8.2.0 to 8.2.2; 8.0.0 to 8.0.16; 7.0 before 7.0.28; 6.0.0 to 6.0.26; 5.0.0 to 5.0.31; 4.4.0 to 4.4.29; all 4.2, 4.0 and 3.6 versions
Upstream Fix
8.2.3; 8.0.17; 7.0.28; 6.0.27; 5.0.32; 4.4.30
Published
December 19, 2025
OSSeva Coverage
Fixed upstream
Description
Mismatched length fields in zlib-compressed protocol headers let an unauthenticated client read uninitialized heap memory from mongod or mongos. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 29 December 2025. MongoDB's workaround is to start mongod or mongos with networkMessageCompressors or net.compression.compressors set to a value that omits zlib, such as snappy,zstd or disabled. CVSS is MongoDB's CVSS 3.1 score as the CNA.
Is your MongoDB deployment affected?
If you're running 8.2.0 to 8.2.2; 8.0.0 to 8.0.16; 7.0 before 7.0.28; 6.0.0 to 6.0.26; 5.0.0 to 5.0.31; 4.4.0 to 4.4.29; all 4.2, 4.0 and 3.6 versions, you need this patch. Book a discovery call to get covered.