Port 27017: MongoDB database server (mongod / mongos)
IANA registers TCP 27017 as mongodb, with UDP 27017 reserved. It is the default port for mongod and mongos, while 27018 and 27019 are defaults for shard and config server roles. MongoDB binaries bind to localhost by default.
Port Details
Security Exposure
A MongoDB instance reachable from untrusted networks without access control exposes its databases to anyone who connects. CVE-2025-14847 allowed an unauthenticated client to read uninitialized heap memory through mismatched zlib compression header lengths, and CISA added it to the Known Exploited Vulnerabilities catalog on December 29, 2025. mongod and mongos bind to localhost by default, so changing bindIp to public interfaces removes that protection.
Hardening
- +Enable access control and enforce authentication with SCRAM or X.509 certificates.
- +Keep bindIp limited to localhost and private application interfaces.
- +Encrypt client and replica set traffic with TLS.
- +Firewall 27017 so only application servers and administrators can connect, and apply MongoDB security releases.
Monitoring
Alert on failed authentication and on connections from addresses outside the application tier. MongoDB Enterprise includes an auditing facility that records user operations and connection events.
MongoDB Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-14847 | Zlib compressed protocol header length confusion may allow memory read | MongoDB Inc. | 8.7 | 83.2% | KEV | 2025-12-19 |
Tools for Auditing and Monitoring MongoDB
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Shodan
FreemiumSearch engine for Internet-connected devices that indexes service banners, open ports, and exposed assets across public IP space.
Related Tool Categories
Data loss prevention, data posture management, and sensitive data discovery and classification platforms.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is port 27017?→
It is the default port for MongoDB's mongod and mongos processes.
Should MongoDB port 27017 be open to the internet?→
No. MongoDB binds to localhost by default, and its security checklist calls for enabling authentication and limiting network exposure.
Is port 27017 TCP or UDP?→
TCP. IANA lists UDP 27017 as reserved.
Which vulnerabilities affect the service on port 27017?→
This database lists 1 CVE related to MongoDB, 1 of them confirmed as exploited by CISA. Examples: CVE-2025-14847.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 27017 is not guaranteed to be MongoDB. Exploited-in-the-wild data from the CISA KEV catalog (CC0).