Dear Tencent Cloud user:
Recently, Tencent Cloud observed that MongoDB published an official security advisory disclosing a high-risk vulnerability identified as CVE-2025-14847. To ensure the security of your data, Tencent Cloud recommends that you review this vulnerability and take appropriate measures promptly.
Vulnerability Details
This vulnerability resides within the network request processing logic of MongoDB Server. When the server has Zlib compression enabled for network transmission, a flaw in buffer management during decompression can be exploited by unauthenticated attackers to read data from MongoDB's memory. This potentially causes the leakage of uninitialized in-memory data fragments.
Affected Scope
This vulnerability affects all minor versions of mainstream major MongoDB versions from 4.2 to 8.0 that were released before December 30, 2025. If your instance was created before this date and its current version falls within the range of "Affected Minor Version" listed below, your instance faces a security risk.
Fixing Recommendations
The TencentDB for MongoDB team has released patched versions to address this vulnerability. To ensure the security of your business, check your instance version against the table below and upgrade the minor version to a suitable secure version as soon as possible by referring to Version Upgrade.
| Major Version | Affected Minor Version | Recommended Secure Version |
|---|---|---|
| 8.0 | WT.80.12.0 | WT.80.12.1 |
| 7.0 | WT.70.12.4 and earlier versions | WT.70.12.5 |
| 6.0 | WT.60.5.3 and earlier versions | WT.60.5.4 |
| 5.0 | WT.50.12.9 and earlier versions | WT.50.12.10 |
| 4.4 | WT.44.13.10 and earlier versions | WT.44.13.11 |
| 4.2 | WT.42.11.20 and earlier versions | WT.42.11.21 |
If you encounter any issues during the upgrade process, please feel free to submit a ticket.
Thank you for your support and trust in Tencent Cloud.
TencentDB Team
![]()