CVE-2025-14847

Publication date 19 December 2025

Last updated 2 January 2026


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Read the notes from the security team

Why is this CVE high priority?

leaks sensitive info

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
mongodb 25.10 questing Not in release
25.04 plucky Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Notes


emitorino

All MongoDB Community Server releases and patches issued after October 16, 2018, are licensed under the Server Side Public License (SSPL). Because the SSPL is not recognized as an open-source license by the Open Source Initiative (OSI), its terms are legally incompatible with the previous GNU Affero General Public License v3.0 (AGPL). All of the upstream commits for this issue are on branches licensed under mongodb's SSPL. zlib, rsync, klibc, and zsync were incorrectly associated with this CVE during initial triage and have been removed.

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N