


Perceptive Security
SOC/SIEM Consultancy

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a…
Published:
29 December 2025 at 00:00:00
Alert date:
29 December 2025 at 20:02:07
Source:
cisa.gov
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability allows unauthenticated clients to read uninitialized heap memory, potentially exposing sensitive information. The flaw affects the protocol-level handling of compressed data and could impact various products using MongoDB components. The vulnerability is tracked as CVE-2025-14847 and has been assigned a high criticality rating due to its potential for unauthorized memory access without authentication requirements.
Technical details
Mitigation steps:
Affected products:
MongoDB
MongoDB Server
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
