top of page
perceptive_background_267k.jpg

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a…

Published:

29 December 2025 at 00:00:00

Alert date:

29 December 2025 at 20:02:07

Source:

cisa.gov

Click to open the original link from this advisory

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability allows unauthenticated clients to read uninitialized heap memory, potentially exposing sensitive information. The flaw affects the protocol-level handling of compressed data and could impact various products using MongoDB components. The vulnerability is tracked as CVE-2025-14847 and has been assigned a high criticality rating due to its potential for unauthorized memory access without authentication requirements.

Technical details

Mitigation steps:

Affected products:

MongoDB
MongoDB Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page