tencent cloud

[TencentDB for MongoDB] Risk Analysis and Fixing Recommendations for MongoDB Security Vulnerability CVE-2025-14847
2026-01-12 18:34:02

Dear Tencent Cloud user:

Recently, Tencent Cloud observed that MongoDB published an official security advisory disclosing a high-risk vulnerability identified as CVE-2025-14847. To ensure the security of your data, Tencent Cloud recommends that you review this vulnerability and take appropriate measures promptly.


Vulnerability Details

This vulnerability resides within the network request processing logic of MongoDB Server. When the server has Zlib compression enabled for network transmission, a flaw in buffer management during decompression can be exploited by unauthenticated attackers to read data from MongoDB's memory. This potentially causes the leakage of uninitialized in-memory data fragments.

  • ● Risk level: critical.
  • ● Primary impact: information disclosure (leakage of sensitive in-memory data).
  • ● Exploitation prerequisites: Attackers can launch attacks without authentication. The risk is significantly heightened if the port (default port number: 27017) of your database instance is exposed to the public network and no strict security policy is set.


Affected Scope

This vulnerability affects all minor versions of mainstream major MongoDB versions from 4.2 to 8.0 that were released before December 30, 2025. If your instance was created before this date and its current version falls within the range of "Affected Minor Version" listed below, your instance faces a security risk.


Fixing Recommendations

The TencentDB for MongoDB team has released patched versions to address this vulnerability. To ensure the security of your business, check your instance version against the table below and upgrade the minor version to a suitable secure version as soon as possible by referring to Version Upgrade.


Major Version Affected Minor Version Recommended Secure Version
8.0 WT.80.12.0 WT.80.12.1
7.0 WT.70.12.4 and earlier versions WT.70.12.5
6.0 WT.60.5.3 and earlier versions WT.60.5.4
5.0 WT.50.12.9 and earlier versions WT.50.12.10
4.4 WT.44.13.10 and earlier versions WT.44.13.11
4.2 WT.42.11.20 and earlier versions WT.42.11.21

If you encounter any issues during the upgrade process, please feel free to submit a ticket.

Thank you for your support and trust in Tencent Cloud.


TencentDB Team

img