Improper Handling of Length Parameter Inconsistency in MongoDB - CVE-2025-14847

 

Improper Handling of Length Parameter Inconsistency in MongoDB - CVE-2025-14847

Published: December 23, 2025 / Updated: February 11, 2026


Vulnerability identifier: #VU120254
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14847
CWE-ID: CWE-130
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to mismatched length fields in Zlib compressed protocol headers. A remote non-authenticated client can read parts of uninitialized heap memory and gain access to sensitive information. 



Affected software

MongoDB
WebSphere Automation
PowerVC
IBM Sterling Transformation Extender
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Storage Defender Copy Data Management
MongoDB Enterprise Advanced with IBM
Storage Protect Plus Server
Splunk Enterprise
Commvault
Ubuntu
mongodb (Ubuntu package)

How to mitigate CVE-2025-14847

Install updates from vendor's website.

MongoDB - addressed in versions 4.4.30, 5.0.32, 6.0.27, 7.0.28, 8.0.17, 8.2.3
WebSphere Automation - update to 1.11.1
MongoDB Enterprise Advanced with IBM - addressed in versions 7.0.28, 8.2.3
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.4.8, 10.0.3, 10.2.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF008
IBM Automation Decision Services - addressed in versions 24.0.0.0.8, 24.0.1.0.8
mongodb (Ubuntu package) - addressed in versions 1:3.6.3-0ubuntu1.4+esm2, 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3+esm1
Storage Protect Plus Server - update to 10.1.18
Commvault - addressed in versions 11.32.129, 11.36.90, 11.40.37

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins