← All CVEs NewScan detects
high

CVE-2025-14847

MongoBleed: unauthenticated zlib-decompression heap memory disclosure

Severity
high
Affected product
MongoDB
Affected versions
MongoDB ≥ 3.6.0, < 8.0.5
Fixed in
MongoDB 8.0.5 / 7.0.16 (confirm against advisory)
Added to NewScan
2026-07-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints MongoDB from its response and reports this CVE when the detected version falls inside the affected range below.

PROVISIONAL RANGE - confirm the exact affected/fixed versions against the MongoDB advisory (SERVER-* / vendor bulletin) + NVD before relying on it; the compression path exists from 3.6+.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →