• News/
  • https://www.bleepingcomputer.com/news/security/mongodb-warns-admins-to-patch-severe-vulnerability-immediately/

MongoDB warns admins to patch severe vulnerability immediately

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 24, 2025
·
Updated

Update 12/26/25: Article updated to correct that the flaw has not been officially classified as an RCE. MongoDB has warned IT admins to immediately patch a high-severity memory-read vulnerability that may be exploited by unauthenticated attackers remotely. Tracked as CVE-2025-14847, the security flaw affects multiple MongoDB and MongoDB Server versions and may be abused by unauthenticated threat actors in low-complexity attacks that don't require user interaction. "An client-side exploit of the Server's zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible," MongoDB's security team said in a Friday advisory. "We strongly suggest you upgrade immediately. If you cannot upgrade immediately, disable zlib compression on the MongoDB Server by starting mongod or mongos with a networkMessageCompressors or a net.compression.compressors option that explicitly omits zlib." CVE-2025-14847 is due to an improper handling of length parameter inconsistency, which according to the associated CWE-130 classification, could potentially allow attackers to execute arbitrary code and potentially gain control of targeted devices in some cases. To patch the security flaw and block potential attacks, admins are advised to immediately upgrade to MongoDB 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30. The vulnerability impacts the following MongoDB versions: The U.S. Cybersecurity and Infra...

Read full article

Affected Software

2 affected components
MongoDB MongoDB>=4.4.30<5.0.32, >=5.0.32<6.0.27, >=6.0.27<7.0.28, >=7.0.28<8.0.17, >=8.0.17<8.2.3
MongoDB MongoDB Server>=4.4.30<5.0.32, >=5.0.32<6.0.27, >=6.0.27<7.0.28, >=7.0.28<8.0.17, >=8.0.17<8.2.3

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity vulnerability in MongoDB that requires immediate patching by IT administrators.

2

What security implications are discussed?

The vulnerability could be exploited by unauthenticated users to potentially access sensitive data within MongoDB.

3

What software versions are affected by the vulnerability?

The vulnerability affects MongoDB versions from 4.4.30 to 8.2.3.

4

What should administrators do in response to the vulnerability?

Administrators are urged to patch their MongoDB installations immediately to mitigate the risk.

5

Has the vulnerability been classified as a remote code execution (RCE) issue?

No, the flaw has not been officially classified as a remote code execution vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203