PatchSiren cyber security CVE debrief
CVE-2025-14847 MongoDB CVE debrief
CVE-2025-14847 is a MongoDB and MongoDB Server vulnerability described as an improper handling of length parameter inconsistency issue. CISA has placed it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as actively important and prioritize mitigation based on vendor guidance.
- Vendor
- MongoDB
- Product
- MongoDB and MongoDB Server
- CVSS
- HIGH 8.7
- CISA KEV
- Listed
- Original CVE published
- 2025-12-29
- Original CVE updated
- 2025-12-29
- Advisory published
- 2025-12-29
- Advisory updated
- 2025-12-29
Who should care
MongoDB administrators, database platform owners, cloud service operators, application teams that embed MongoDB, and security teams responsible for vulnerability response and asset remediation.
Technical summary
The official records identify the issue as an improper handling of length parameter inconsistency vulnerability in MongoDB and MongoDB Server. The supplied corpus does not include affected version ranges, exploit mechanics, or remediation specifics, but CISA’s KEV listing indicates known exploitation and directs organizations to apply vendor mitigations or discontinue use if mitigations are unavailable.
Defensive priority
High
Recommended defensive actions
- Identify all MongoDB and MongoDB Server deployments, including managed and embedded uses.
- Check the official CVE and NVD records for any version-specific impact information and vendor-linked guidance.
- Apply mitigations per vendor instructions as referenced by CISA as soon as practical.
- If mitigations are unavailable, follow CISA guidance to discontinue use of the product or service.
- For cloud services, follow applicable BOD 22-01 guidance and coordinate with your service provider.
- Track exposure status until remediation is complete and verify that affected instances are no longer vulnerable.
Evidence notes
This debrief is based only on the supplied official/authoritative records: the CISA KEV entry, the CVE record, and the NVD detail page. The CISA source lists MongoDB as the vendor project, MongoDB and MongoDB Server as the product, date added 2025-12-29, due date 2026-01-19, and required action to apply vendor mitigations or discontinue use if mitigations are unavailable. The corpus does not provide CVSS scoring, affected version ranges, or product-specific remediation steps, so those details are intentionally not inferred.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14847 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14847
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14847 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14847
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.