high
CVE-2025-14847
MongoBleed: unauthenticated zlib-decompression heap memory disclosure
- Severity
- high
- Affected product
- MongoDB
- Affected versions
- MongoDB ≥ 3.6.0, < 8.0.5
- Fixed in
- MongoDB 8.0.5 / 7.0.16 (confirm against advisory)
- Added to NewScan
- 2026-07-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints MongoDB from its response and reports this CVE when the detected version falls inside the affected range below.
PROVISIONAL RANGE - confirm the exact affected/fixed versions against the MongoDB advisory (SERVER-* / vendor bulletin) + NVD before relying on it; the compression path exists from 3.6+.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →