{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-14847",
  "revision": 1,
  "title": "MongoDB Server — uninitialised heap read from compressed headers",
  "summary": "Mismatched length fields in compressed protocol headers let an unauthenticated client read uninitialised heap memory out of MongoDB Server, exposing whatever happened to be sitting there. Fixed across the 5.0 to 8.2 branches.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 8.7,
    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
    "version": "4.0"
  },
  "epss": 0.83218,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-12-29",
    "prerequisites": "Network access to the database port; no credentials needed."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "MongoDB Server 7.0.28",
      "MongoDB Server 8.0.17",
      "MongoDB Server 8.2.3",
      "MongoDB Server 6.0.27",
      "MongoDB Server 5.0.32"
    ]
  },
  "kill_chain": "collection",
  "recommended_action": "Upgrade MongoDB Server to 7.0.28, 8.0.17, 8.2.3, 6.0.27 or 5.0.32 now; keep the database port off any network that does not need to reach it.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-14847",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-14847",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-14847",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14847",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://jira.mongodb.org/browse/SERVER-115508"
    },
    {
      "type": "exploit",
      "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-detection-script-heap-memory-exposure-in-mongodb-server"
    },
    {
      "type": "exploit",
      "url": "https://www.vicarius.io/vsociety/posts/cve-2025-14847-mitigation-script-heap-memory-exposure-in-mongodb-server"
    }
  ],
  "published_at": "2025-12-19T11:15:49.277Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "mongodb",
    "database",
    "memory-disclosure",
    "kev"
  ]
}
