Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/mongodb/mongo | affected | >= a57d8e71e6998a2d0afde7edc11bd23e5661c915, < 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 | vendor fix → 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 | osv | |
| https://github.com/mongodb/mongo | affected | >= 1184f004a99660de6f5e745573419bda8a28c0e9, < 1c23b749ffbe99573fd065904a0a87368c1c6523 | vendor fix → 1c23b749ffbe99573fd065904a0a87368c1c6523 | osv | |
| https://github.com/mongodb/mongo | affected | >= e61bf27c2f6a83fed36e5a13c008a32d563babe2, < 2884bcf91236785867396e7916eeb873c59f84cd | vendor fix → 2884bcf91236785867396e7916eeb873c59f84cd | osv | |
| https://github.com/mongodb/mongo | affected | >= 37d84072b5c5b9fd723db5fa133fb202ad2317f1, < 5393ef6c933e57093d11f704e611195301a967dd | vendor fix → 5393ef6c933e57093d11f704e611195301a967dd | osv | |
| https://github.com/mongodb/mongo | affected | >= b41cda4fe697dce6fd9b83b3805362ccc02fbeb3, < fe4a0b8cf49fd664128bcf668c046292c8e8eb80 | vendor fix → fe4a0b8cf49fd664128bcf668c046292c8e8eb80 | osv | |
| https://github.com/mongodb/mongo | affected | >= b993867dce63dd366cd93e60f3f425ed716f6497, < 029d8f99bf1e828b5327946b9c820bf493f466f1 | vendor fix → 029d8f99bf1e828b5327946b9c820bf493f466f1 | osv | |
| mongodb | affected | >= 4.4.0, < 4.4.30 | vendor fix → 4.4.30 | osv BIT-mongodb-2025-14847 | |
| mongodb | affected | >= 5.0.0, < 5.0.32 | vendor fix → 5.0.32 | osv BIT-mongodb-2025-14847 | |
| mongodb | affected | >= 6.0.0, < 6.0.27 | vendor fix → 6.0.27 | osv BIT-mongodb-2025-14847 | |
| mongodb | affected | >= 7.0.0, < 7.0.28 | vendor fix → 7.0.28 | osv BIT-mongodb-2025-14847 | |
| mongodb | affected | >= 8.0.0, < 8.0.17 | vendor fix → 8.0.17 | osv BIT-mongodb-2025-14847 | |
| mongodb | affected | >= 8.2.0, < 8.2.3 | vendor fix → 8.2.3 | osv BIT-mongodb-2025-14847 | |
| https://github.com/mongodb/mongo | fixed | 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 | vendor fix → 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 | osv | |
| https://github.com/mongodb/mongo | fixed | 1c23b749ffbe99573fd065904a0a87368c1c6523 | vendor fix → 1c23b749ffbe99573fd065904a0a87368c1c6523 | osv | |
| https://github.com/mongodb/mongo | fixed | 2884bcf91236785867396e7916eeb873c59f84cd | vendor fix → 2884bcf91236785867396e7916eeb873c59f84cd | osv | |
| https://github.com/mongodb/mongo | fixed | 5393ef6c933e57093d11f704e611195301a967dd | vendor fix → 5393ef6c933e57093d11f704e611195301a967dd | osv | |
| https://github.com/mongodb/mongo | fixed | fe4a0b8cf49fd664128bcf668c046292c8e8eb80 | vendor fix → fe4a0b8cf49fd664128bcf668c046292c8e8eb80 | osv | |
| https://github.com/mongodb/mongo | fixed | 029d8f99bf1e828b5327946b9c820bf493f466f1 | vendor fix → 029d8f99bf1e828b5327946b9c820bf493f466f1 | osv | |
| mongodb | fixed | 4.4.30 | vendor fix → 4.4.30 | osv BIT-mongodb-2025-14847 | |
| mongodb | fixed | 5.0.32 | vendor fix → 5.0.32 | osv BIT-mongodb-2025-14847 | |
| mongodb | fixed | 6.0.27 | vendor fix → 6.0.27 | osv BIT-mongodb-2025-14847 | |
| mongodb | fixed | 7.0.28 | vendor fix → 7.0.28 | osv BIT-mongodb-2025-14847 | |
| mongodb | fixed | 8.0.17 | vendor fix → 8.0.17 | osv BIT-mongodb-2025-14847 | |
| mongodb | fixed | 8.2.3 | vendor fix → 8.2.3 | osv BIT-mongodb-2025-14847 | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 8.2, < 8.2.3 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 8.0, < 8.0.17 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 7.0, < 7.0.28 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 6.0, < 6.0.27 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 5.0, < 5.0.32 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | >= 4.4, < 4.4.30 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | 4.2 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | 4.0 | none available | cve_cna | |
| MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server | affected | 3.6 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.