Severe vulnerability in MongoDB, update immediately
This message is intended for U-M IT staff who are responsible for university systems running MongoDB.
Summary
MongoDB has warned IT admins to immediately patch a high-severity memory-read vulnerability that may be exploited by unauthenticated attackers remotely. Exploit code has been made publicly available and widespread exploitation may occur.
Problem
Tracked as CVE-2025-14847, the security flaw affects multiple MongoDB and MongoDB Server versions and may be abused by unauthenticated threat actors in low-complexity attacks that don't require user interaction.
CVE-2025-14847 is due to an improper handling of length parameter inconsistency, which according to the associated CWE-130 classification, could potentially allow attackers to execute arbitrary code and potentially gain control of targeted devices in some cases.
Threats
Exploit code has been made publicly available for this vulnerability. The exploit code facilitates the retrieval of secrets, such as database passwords. Widespread exploitation to steal credentials is likely in the near term. Exploitation to perform remote code execution is possible, but at the time of publishing this alert, is not yet known to be occurring.
Affected Versions
The vulnerability impacts the following MongoDB versions:
- MongoDB 8.2.0 through 8.2.3
- MongoDB 8.0.0 through 8.0.16
- MongoDB 7.0.0 through 7.0.26
- MongoDB 6.0.0 through 6.0.26
- MongoDB 5.0.0 through 5.0.31
- MongoDB 4.4.0 through 4.4.29
- All MongoDB Server v4.2 versions
- All MongoDB Server v4.0 versions
- All MongoDB Server v3.6 versions
Action Items
Upgrade MongoDB immediately to 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30. If you cannot upgrade immediately, disable zlib compression on the MongoDB Server by starting mongod or mongos with a networkMessageCompressors or a net.compression.compressors option that explicitly omits zlib.
How We Protect U-M
ITS is patching ITS-managed MongoDB installations. MiServer customers will need to identify their non-ITS-Managed and Unmanaged MiServer systems running vulnerable versions of MongoDB and apply updates.
Information for Users
If you have installed the MongoDB service on non-U-M devices, please check for updates and install them.
Questions, Concerns, Reports
Please contact ITS Information Assurance through the ITS Service Center.