Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-14847

MongoDB Server: unauthenticated heap memory read through zlib-compressed message headers (MongoBleed)

Technology

MongoDB

CVSS Score

7.5 / 10.0

Affected Versions

8.2.0 to 8.2.2; 8.0.0 to 8.0.16; 7.0 before 7.0.28; 6.0.0 to 6.0.26; 5.0.0 to 5.0.31; 4.4.0 to 4.4.29; all 4.2, 4.0 and 3.6 versions

Upstream Fix

8.2.3; 8.0.17; 7.0.28; 6.0.27; 5.0.32; 4.4.30

Published

December 19, 2025

OSSeva Coverage

Fixed upstream

Description

Mismatched length fields in zlib-compressed protocol headers let an unauthenticated client read uninitialized heap memory from mongod or mongos. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 29 December 2025. MongoDB's workaround is to start mongod or mongos with networkMessageCompressors or net.compression.compressors set to a value that omits zlib, such as snappy,zstd or disabled. CVSS is MongoDB's CVSS 3.1 score as the CNA.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 8.2.0 to 8.2.2; 8.0.0 to 8.0.16; 7.0 before 7.0.28; 6.0.0 to 6.0.26; 5.0.0 to 5.0.31; 4.4.0 to 4.4.29; all 4.2, 4.0 and 3.6 versions, you need this patch. Book a discovery call to get covered.