mongodb-org-database is vulnerable to Disclosure of Sensitive Heap Memory Data
87
High Risk
Affected versions of MongoDB Server are vulnerable to an unauthenticated information disclosure (CVE-2025-14847) due to improper handling of zlib-compressed network traffic, where malformed compressed frames can cause MongoDB to include uninitialized heap memory in server responses. An attacker with only network access and no authentication can trigger this behavior when compression is enabled, potentially exposing fragments of previous query results, internal server state, or sensitive values from process memory. The issue affects multiple MongoDB releases up to recent patch levels and is fixed in newer versions; mitigation requires upgrading, restricting network exposure, or disabling zlib compression until patches are applied.
You are affected if you are using a version that falls within the vulnerable range.
mongodb-org-database is vulnerable to Disclosure of Sensitive Heap Memory Data in versions 0.0.1 - 4.4.29, 5.0.0 - 5.0.31, 6.0.0 - 6.0.26, 7.0.0 - 7.0.27, 8.0.0 - 8.0.16 and 8.1.0 - 8.2.2.
Upgrade the mongodb-org-database library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant