Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14847

98
FAUCET Score

CVE-2025-14847, dubbed "MongoBleed," is a critical vulnerability affecting numerous MongoDB Server versions, where mismatched length fields in Zlib compressed protocol headers can lead to unauthenticated heap memory disclosure. With a CVSS score of 7.5 (High), this flaw allows an unauthenticated attacker to read sensitive information from memory without user interaction, posing a significant risk of data exposure. This vulnerability is actively exploited in the wild, with public exploit modules available (e.g., Metasploit), and has garnered extensive community discussion and media coverage, emphasizing the urgent need for patching.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.6.0, < 4.4.30CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.32CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.0.27CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
>= 7.0.0, < 7.0.28CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
>= 8.0.0, < 8.0.17CPE matchmatch criteria
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
83.01%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Dec 29, 2025
Metasploit: MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed · Dec 19, 2025
Nuclei: CVE-2025-14847 · Dec 27, 2025
This CVE's current EPSS score of 0.8301 is in the 100th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
freshrsspatch availablevia llm_extracted
qdrantpatch availablevia llm_extracted
symantecpatch availablevia llm_extracted
verbbpatch availablevia llm_extracted
watchguardpatch availablevia llm_extracted
View patch

Vendor Advisories (9)

qdrantllm-qdrant-137cbe216395c34d

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
barracudallm-barracuda-1f8b3c0a48075bdb

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
symantecllm-symantec-5642fdc1a4f5e646

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
verbbllm-verbb-6f628615eb1df1b2

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
consulllm-consul-c010112bf9828deb

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
clamavllm-clamav-c4c0e32840929d4f

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
boschllm-bosch-915f69f37b0401df

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
freshrssllm-freshrss-2fca9d2d9735c844

MongoBleed: MongoDB Memory Disclosure Vulnerability (CVE-2025-14847)

Feb 10, 2026
watchguardllm-watchguard-26014a4120d6cbe8

Security Advisory on Omada Controller Exposure to MongoBleed

References

cisa.gov / known-exploited-vulnerabilities-catalog
Third Party AdvisoryUS Government Resource
smartkeyss.com / post/mongobleed-pre-auth-memory-disclosure-via-op_compressed-in-mongodb-cve-2025-14847
Technical DescriptionThird Party Advisory
vicarius.io / vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server
ExploitThird Party Advisory
vicarius.io / vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server
ExploitThird Party Advisory
openwall.com / lists/oss-security/2025/12/29/21
Mailing List
jira.mongodb.org / browse/SERVER-115508
Issue TrackingPatchVendor Advisory