CyberzSOC

Applicability
← Back to CVE-2025-14847

CVE-2025-14847

In CISA KEV MongoDB

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-12
12 affected 12 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2026-02-26
9 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (33)

Product Status Versions Remediation Source
https://github.com/mongodb/mongo affected >= a57d8e71e6998a2d0afde7edc11bd23e5661c915, < 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 vendor fix → 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 osv
https://github.com/mongodb/mongo affected >= 1184f004a99660de6f5e745573419bda8a28c0e9, < 1c23b749ffbe99573fd065904a0a87368c1c6523 vendor fix → 1c23b749ffbe99573fd065904a0a87368c1c6523 osv
https://github.com/mongodb/mongo affected >= e61bf27c2f6a83fed36e5a13c008a32d563babe2, < 2884bcf91236785867396e7916eeb873c59f84cd vendor fix → 2884bcf91236785867396e7916eeb873c59f84cd osv
https://github.com/mongodb/mongo affected >= 37d84072b5c5b9fd723db5fa133fb202ad2317f1, < 5393ef6c933e57093d11f704e611195301a967dd vendor fix → 5393ef6c933e57093d11f704e611195301a967dd osv
https://github.com/mongodb/mongo affected >= b41cda4fe697dce6fd9b83b3805362ccc02fbeb3, < fe4a0b8cf49fd664128bcf668c046292c8e8eb80 vendor fix → fe4a0b8cf49fd664128bcf668c046292c8e8eb80 osv
https://github.com/mongodb/mongo affected >= b993867dce63dd366cd93e60f3f425ed716f6497, < 029d8f99bf1e828b5327946b9c820bf493f466f1 vendor fix → 029d8f99bf1e828b5327946b9c820bf493f466f1 osv
mongodb affected >= 4.4.0, < 4.4.30 vendor fix → 4.4.30 osv BIT-mongodb-2025-14847
mongodb affected >= 5.0.0, < 5.0.32 vendor fix → 5.0.32 osv BIT-mongodb-2025-14847
mongodb affected >= 6.0.0, < 6.0.27 vendor fix → 6.0.27 osv BIT-mongodb-2025-14847
mongodb affected >= 7.0.0, < 7.0.28 vendor fix → 7.0.28 osv BIT-mongodb-2025-14847
mongodb affected >= 8.0.0, < 8.0.17 vendor fix → 8.0.17 osv BIT-mongodb-2025-14847
mongodb affected >= 8.2.0, < 8.2.3 vendor fix → 8.2.3 osv BIT-mongodb-2025-14847
https://github.com/mongodb/mongo fixed 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 vendor fix → 1ae4c9990dbc5711f3500748f0c3f8b5d375d8c0 osv
https://github.com/mongodb/mongo fixed 1c23b749ffbe99573fd065904a0a87368c1c6523 vendor fix → 1c23b749ffbe99573fd065904a0a87368c1c6523 osv
https://github.com/mongodb/mongo fixed 2884bcf91236785867396e7916eeb873c59f84cd vendor fix → 2884bcf91236785867396e7916eeb873c59f84cd osv
https://github.com/mongodb/mongo fixed 5393ef6c933e57093d11f704e611195301a967dd vendor fix → 5393ef6c933e57093d11f704e611195301a967dd osv
https://github.com/mongodb/mongo fixed fe4a0b8cf49fd664128bcf668c046292c8e8eb80 vendor fix → fe4a0b8cf49fd664128bcf668c046292c8e8eb80 osv
https://github.com/mongodb/mongo fixed 029d8f99bf1e828b5327946b9c820bf493f466f1 vendor fix → 029d8f99bf1e828b5327946b9c820bf493f466f1 osv
mongodb fixed 4.4.30 vendor fix → 4.4.30 osv BIT-mongodb-2025-14847
mongodb fixed 5.0.32 vendor fix → 5.0.32 osv BIT-mongodb-2025-14847
mongodb fixed 6.0.27 vendor fix → 6.0.27 osv BIT-mongodb-2025-14847
mongodb fixed 7.0.28 vendor fix → 7.0.28 osv BIT-mongodb-2025-14847
mongodb fixed 8.0.17 vendor fix → 8.0.17 osv BIT-mongodb-2025-14847
mongodb fixed 8.2.3 vendor fix → 8.2.3 osv BIT-mongodb-2025-14847
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 8.2, < 8.2.3 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 8.0, < 8.0.17 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 7.0, < 7.0.28 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 6.0, < 6.0.27 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 5.0, < 5.0.32 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected >= 4.4, < 4.4.30 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected 4.2 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected 4.0 none available cve_cna
MongoDB Inc./MongoDB Server MongoDB Inc. · MongoDB Server affected 3.6 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.