{"api_version":"v1","generated_at":"2026-10-08T19:40:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-mongodb-mongodb-and-mongodb-server-611ed5c58c2c","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"MongoDB and MongoDB Server","next_cursor":null,"observations":[{"affected":"MongoDB Server: 8.2 < 8.2.3, 8.0 < 8.0.17, 7.0 < 7.0.28, 6.0 < 6.0.27, 5.0 < 5.0.32, 4.4 < 4.4.30, 4.2, 4.0, 3.6","affected_versions_present":true,"cve_id":"CVE-2025-14847","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-14847","fixed":"The Cyber Centre recommends that organizations upgrade affected MongoDB Server(s) to a fixed version: Affected product Affected version Fixed version MongoDB 8.2 8.2.0 \u2013 8.2.2 8.2.3 MongoDB 8.0 8.0.0 \u2013 8.0.16 8.0.17 MongoDB 7.0 7.0.0 \u2013 7.0.27 7.0.28 MongoDB 6.0 6.0.0 \u2013 6.0.26 6.0.27 MongoDB 5.0 5.0.0 \u2013 5.0.31 5.0.32 MongoDB 4.4 4.4.0 \u2013 4.4.29 4.4.30 MongoDB 4.2 All versions No vendor fix; upgrade to fixed version MongoDB 4.0 All versions No vendor fix; upgrade to fixed version MongoDB 3.6 All versions No vendor fix; upgrade to fixed version If immediate patching is not possible, reduce exposure by: Disabling zlib compression by starting mongod/mongos with networkMessageCompressors or net.compression.compressors options that omit zlib (use snappy or zstd). Restricting network access to MongoDB to trusted IPs ; avoid direct internet exposure. As a precaution, it is recommended that organizations review their logs for potential signs of compromise including: Monitor MongoDB logs for anomalous pre-authentication connections or unexpected errors. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre\u2019s Top 10 IT Security Actions with an emphasis on the following topics Footnote 6 . Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca .","last_modified":"2026-02-26T16:07:25.054Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/al25-021-vulnerability-affecting-mongodb-cve-2025-14847","primary_source":"","published":"2025-12-19T11:00:22.465Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"MongoDB"}}
