Skip to main content

CVE detail

CVE-2025-14847

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

CVSS 8.7 · HighBuzz score 80.5KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 80.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 5.5
Mention score
30.0
19 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
5.5
1 repos · best confidence 0.99
Best PoC traction
1
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
19 source links · newest first
  • ABB Ability ZenonCISA Alerts

    Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Serve

    governmentwww.cisa.govAug 6, 2026, 12:00 PM
  • task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst

    vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM
  • Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7.

    vendorunit42.paloaltonetworks.comJan 13, 2026, 8:30 PM
  • CVE-2025-14847Horizon3.ai

    MongoDB Server Uninitialized Heap Memory Disclosure (MongoBleed) | Active Exploitation

    exploithorizon3.aiJan 6, 2026, 5:31 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. French authorities investigate AI ‘undressing’ deepfakes on X Thousands of ColdFusion exploit attempts spotted during Christmas […]

    newssecurityaffairs.comJan 4, 2026, 1:06 PM
  • MongoBleed (CVE-2025-14847) lets attackers remotely leak memory from unpatched MongoDB servers using zlib compression, without authentication. A critical vulnerability, CVE-2025-14847 (MongoBleed), was disclosed right after Christmas, an unwelcome “gift” for the cybersecurity community, impacting MongoDB Server deployments that use zlib network compression. MongoDB is a popular open-source NoSQL database used to store and manage data […]

    newssecurityaffairs.comDec 31, 2025, 8:22 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a MongoDB Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a MongoDB Server vulnerability, tracked as CVE-2025-14847 (CVSS Score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. The recently disclosed MongoDB vulnerability CVE-2025-14847 (aka MongoBleed) is being actively exploited, with more […]

    newssecurityaffairs.comDec 30, 2025, 8:33 AM
  • A recently disclosed MongoDB flaw (MongoBleed) is under active exploitation, with over 87,000 potentially vulnerable instances exposed worldwide. A newly disclosed MongoDB vulnerability, tracked as CVE-2025-14847 (aka MongoBleed, CVSS score of 8.7), is being actively exploited, with more than 87,000 potentially vulnerable instances identified worldwide. Cybersecurity researcher Joe Desimone published a proof-of-concept exploit for this vulnerability […]

    newssecurityaffairs.comDec 29, 2025, 12:56 PM
  • 29th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 29th December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romanian Waters, the country’s national water management authority, was hit by a ransomware attack that resulted in nearly 1,000 computer systems across national and regional offices being encrypted. The attack affected geographic […]

    vendorresearch.checkpoint.comDec 29, 2025, 11:33 AM
  • Dubbed MongoBleed, the high-severity flaw allows unauthenticated, remote attackers to leak sensitive information from MongoDB servers.

    newswww.securityweek.comDec 29, 2025, 9:54 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. LangChain core vulnerability allows prompt injection and data exposure NPM package with 56,000 downloads compromises WhatsApp […]

    newssecurityaffairs.comDec 28, 2025, 9:20 AM
  • Document database vendor MongoDB has advised customers to update immediately following the discovery of a flaw that could allow unauthenticated users to read uninitialized heap memory. Designated CVE-2025-14847, the bug, mismatched length fields in zlib compressed protocol headers, could allow an attacker to execute arbitrary code and potentially seize control of a device. The flaw […]

    newswww.csoonline.comDec 26, 2025, 8:19 PM
  • MongoDB addressed a high-severity vulnerability that can be exploited to achieve remote code execution on vulnerable servers. MongoDB addressed a high-severity vulnerability, tracked as CVE-2025-14847 (CVSS score 8.7), an unauthenticated, remote attacker can exploit the issue to execute arbitrary code on vulnerable servers. “An client-side exploit of the Server’s zlib implementation can return uninitialized heap […]

    newssecurityaffairs.comDec 25, 2025, 10:12 AM
  • No excerpt available.

    Mitigationwww.cisa.govDec 19, 2025, 11:15 AM
  • No excerpt available.

    Exploitwww.vicarius.ioDec 19, 2025, 11:15 AM
  • No excerpt available.

    Exploitwww.vicarius.ioDec 19, 2025, 11:15 AM
  • No excerpt available.

    Exploitwww.smartkeyss.comDec 19, 2025, 11:15 AM
  • No excerpt available.

    Exploitwww.openwall.comDec 19, 2025, 11:15 AM
  • https://jira.mongodb.org/browse/SERVER-115508jira.mongodb.org

    No excerpt available.

    Exploitjira.mongodb.orgDec 19, 2025, 11:15 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 1 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-14587

    Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol…

    CVSS 5.5 · Medium
    1 mention
  • CVE-2026-67292

    FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fi…

    CVSS 9.3 · Critical
    3 mentions
  • CVE-2026-62424

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfs…

    CVSS 5.5 · Medium
    1 mention
  • CVE-2026-62423

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfs…

    CVSS 5.5 · Medium
    1 mention
  • CVE-2026-26081

    HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

    CVSS 4.8 · Medium
    3 mentions
  • CVE-2026-54466

    websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that all…

    CVSS 9.2 · Critical
    2 mentions