CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
- Affected products
- Linuxmint, Mongodb Server, Mongodb, Red Os, Ubuntu
- Mongodb
- < 4.4.30, 5.0.32, 6.0.27, 7.0.28, 8.0.17, 8.2.3
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 83.2% (100th percentile)
- Weakness
- CWE-130
- NVD status
- Analyzed
- Published
- 2025-12-19
CVE-2025-14847 at NVD
78 known exploits for CVE-2025-14847
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-14847
CVE-2025-14847-mongobleed
CVE-2025-14847_Expolit
CVE-2025-14847
CVE-2025-14847
mongobleed-exploit-CVE-2025-14847
MongoBleed
CVE-2025-14847
CVE-2025-14847_Expolit
mongobleed-detector
CVE-2025-14847---MongoBleed
MongoBleed-exploit
CVE-2025-14847
CVE-2025-14847
CVE-2025-14847
mongobleed
CVE-2025-14857-MongoBleed
MongoBleed-CVE-2025-14847
Mongobleed-Detector-CVE-2025-14847
mongobleed
CVE-2025-14847
CVE-2025-14847-MongoBleed
CVE-2025-14847
cve-2025-14847
CVE-2025-14847
CVE-2025-14847-MongoDB
MongoBLEED---CVE-2025-14847-POC-
CVE-2025-14847_Expolit
mongobleed
MongoDeepDive
mongobleedburp
CVE-2025-14847-MongoBleed-Exploit
mongobleed-exploit-CVE-2025-14847
CVE-2025-14847
CVE-2025-14847-PoC
MongoBleed-CVE-2025-14847-Fully-Automated-scanner
mongobleed-scanner
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026
database-sentinel
MongoBleed-DFIR-Triage-Script-CVE-2025-14847
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for SQL Injection in Mjdm Majordomo
π MongoDB BSON Decompression OP_COMPRESSED Memory Disclosure
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for CVE-2026-24061
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for CVE-2025-14857
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for Improper Handling of Length Parameter Inconsistency in Mongodb
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
Exploit for CVE-2025-14847
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed