Improper Handling of Length Parameter Inconsistency in MongoDB - CVE-2025-14847
Published: December 23, 2025 / Updated: February 11, 2026
Vulnerability identifier: #VU120254
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14847
CWE-ID: CWE-130
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to mismatched length fields in Zlib compressed protocol headers. A remote non-authenticated client can read parts of uninitialized heap memory and gain access to sensitive information.
Affected software
MongoDB
WebSphere Automation
PowerVC
IBM Sterling Transformation Extender
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Storage Defender Copy Data Management
MongoDB Enterprise Advanced with IBM
Storage Protect Plus Server
Splunk Enterprise
Commvault
Ubuntu
mongodb (Ubuntu package)
WebSphere Automation
PowerVC
IBM Sterling Transformation Extender
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Storage Defender Copy Data Management
MongoDB Enterprise Advanced with IBM
Storage Protect Plus Server
Splunk Enterprise
Commvault
Ubuntu
mongodb (Ubuntu package)
How to mitigate CVE-2025-14847
Install updates from vendor's website.
MongoDB - addressed in versions 4.4.30, 5.0.32, 6.0.27, 7.0.28, 8.0.17, 8.2.3
WebSphere Automation - update to 1.11.1
MongoDB Enterprise Advanced with IBM - addressed in versions 7.0.28, 8.2.3
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3, 10.2.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF008
IBM Automation Decision Services - addressed in versions 24.0.0.0.8, 24.0.1.0.8
mongodb (Ubuntu package) - addressed in versions 1:3.6.3-0ubuntu1.4+esm2, 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3+esm1
Storage Protect Plus Server - update to 10.1.18
Commvault - addressed in versions 11.32.129, 11.36.90, 11.40.37
WebSphere Automation - update to 1.11.1
MongoDB Enterprise Advanced with IBM - addressed in versions 7.0.28, 8.2.3
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3, 10.2.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF008
IBM Automation Decision Services - addressed in versions 24.0.0.0.8, 24.0.1.0.8
mongodb (Ubuntu package) - addressed in versions 1:3.6.3-0ubuntu1.4+esm2, 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3+esm1
Storage Protect Plus Server - update to 10.1.18
Commvault - addressed in versions 11.32.129, 11.36.90, 11.40.37
Links to Public Exploits and PoC-codes
- Exploit #12357 - CVE-2025-14847_Expolit (February 6, 2026)
- Exploit #12297 - CVE-2025-14847 (? Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.) (January 16, 2026)
- Exploit #12267 - mongobleed (CVE-2025-14847 exploit for MongoDB heap memory disclosure) (January 9, 2026)
- Exploit #12262 - CVE-2025-14847-MongoBleed-Exploit (CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC) (January 9, 2026)
- Exploit #12216 - MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed (December 30, 2025)
External References
Related Security Bulletins
- Information disclosure in MongoDB server
- IBM WebSphere Automation update for MongoDB
- Splunk Enterprise update for MongoDB
- IBM PowerVC update for Zlib
- Commvault update for MongoDB
- IBM Sterling Transformation Extender update for Zlib
- IBM Storage Defender Copy Data Management update for Zlib
- MongoDB Enterprise Advanced with IBM update for Zlib
- IBM Automation Decision Services update for Zlib
- IBM Cloud Pak for Business Automation update for Zlib
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Ubuntu update for mongodb