CVE-2025-14847 | MongoDB Server up to 8.2.2 Zlib Protocol Header message_compressor_zlib.cpp decompressData length MongoBleed length parameter (Nessus ID 279586 / WID-SEC-2025-2905)
A vulnerability marked as problematic has been reported in MongoDB Server up to 8.2.2. The affected element is the function ZlibMessageCompressor::decompressData of the file src/mongo/transport/message_compressor_zlib.cpp of the component Zlib Protocol Header Handler. The manipulation of the argument length leads to improper handling of length parameter inconsistency.
This vulnerability is uniquely identified as CVE-2025-14847. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.