PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14847 MongoDB CVE debrief

CVE-2025-14847 is a MongoDB and MongoDB Server vulnerability described as an improper handling of length parameter inconsistency issue. CISA has placed it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as actively important and prioritize mitigation based on vendor guidance.

Vendor
MongoDB
Product
MongoDB and MongoDB Server
CVSS
HIGH 8.7
CISA KEV
Listed
Original CVE published
2025-12-29
Original CVE updated
2025-12-29
Advisory published
2025-12-29
Advisory updated
2025-12-29

Who should care

MongoDB administrators, database platform owners, cloud service operators, application teams that embed MongoDB, and security teams responsible for vulnerability response and asset remediation.

Technical summary

The official records identify the issue as an improper handling of length parameter inconsistency vulnerability in MongoDB and MongoDB Server. The supplied corpus does not include affected version ranges, exploit mechanics, or remediation specifics, but CISA’s KEV listing indicates known exploitation and directs organizations to apply vendor mitigations or discontinue use if mitigations are unavailable.

Defensive priority

High

Recommended defensive actions

  • Identify all MongoDB and MongoDB Server deployments, including managed and embedded uses.
  • Check the official CVE and NVD records for any version-specific impact information and vendor-linked guidance.
  • Apply mitigations per vendor instructions as referenced by CISA as soon as practical.
  • If mitigations are unavailable, follow CISA guidance to discontinue use of the product or service.
  • For cloud services, follow applicable BOD 22-01 guidance and coordinate with your service provider.
  • Track exposure status until remediation is complete and verify that affected instances are no longer vulnerable.

Evidence notes

This debrief is based only on the supplied official/authoritative records: the CISA KEV entry, the CVE record, and the NVD detail page. The CISA source lists MongoDB as the vendor project, MongoDB and MongoDB Server as the product, date added 2025-12-29, due date 2026-01-19, and required action to apply vendor mitigations or discontinue use if mitigations are unavailable. The corpus does not provide CVSS scoring, affected version ranges, or product-specific remediation steps, so those details are intentionally not inferred.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14847 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14847

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14847 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14847

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.