• News/
  • https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-rce-flaw-immediately/

MongoDB warns admins to patch severe RCE flaw immediately

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 24, 2025
·
Updated

MongoDB has warned IT admins to immediately patch a high-severity vulnerability that may be exploited in remote code execution (RCE) attacks targeting vulnerable servers. Tracked as CVE-2025-14847, this security flaw affects multiple MongoDB and MongoDB Server versions and may be exploited by unauthenticated threat actors in low-complexity attacks that don't require user interaction. CVE-2025-14847 is due to an improper handling of length parameter inconsistency, which can allow attackers to execute arbitrary code and potentially gain control of targeted devices. To patch the security flaw and block potential attacks, admins are advised to immediately upgrade to MongoDB 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30. The vulnerability impacts the following MongoDB versions: "An client-side exploit of the Server's zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible," MongoDB's security team said in a Friday advisory. "We strongly suggest you upgrade immediately. If you cannot upgrade immediately, disable zlib compression on the MongoDB Server by starting mongod or mongos with a networkMessageCompressors or a net.compression.compressors option that explicitly omits zlib." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a MongoDB mongo-express RCE flaw (CVE-2019-10758) to its catalog of known exploited vulnerabilities four years ago, tagging...

Read full article

Affected Software

1 affected component
MongoDB MongoDB>=4.4.30, >=5.0.32, >=6.0.27, >=7.0.28, >=8.0.17, >=8.2.3

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity remote code execution vulnerability in MongoDB that requires immediate patching.

2

What is the identified vulnerability in MongoDB?

The vulnerability is tracked as CVE-2025-14847 and may lead to remote code execution attacks.

3

Which versions of MongoDB are affected by the RCE flaw?

The vulnerability affects multiple MongoDB and MongoDB Server versions.

4

What action should IT admins take regarding this vulnerability?

IT admins are advised to immediately patch their MongoDB installations to mitigate the risk.

5

What potential risks does CVE-2025-14847 pose to servers?

CVE-2025-14847 may be exploited by unauthenticated attackers, potentially leading to severe security breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203