Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server versions prior to the respective patch releases — including v7.0 prior to 7.0.28, v8.0 prior to 8.0.17, v8.2 prior to 8.2.3, v6.0 prior to 6.0.27, v5.0 prior to 5.0.32, v4.4 prior to 4.4.30, and v4.2, v4.0 and v3.6 series at and above their initial releases — potentially exposing sensitive heap memory under crafted Zlib compressed protocol requests.
The IONIX research team developed a simulation to validate exposure to CVE‑2025‑14847. Confirmed findings are listed in this post.
References:

