Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mongobleed-exploit-CVE-2025-14847 — Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools | Kitploit
Tools/GitHubGitHub/security-phoenix-demo/mongobleed-exploit-cve-2025-14847
Vulnerability ScannersCode AnalysisExploitationLearning & EducationDatabase SecurityLabs & Practice
GitHubsecurity-phoenix-demo/mongobleed-exploit-cve-2025-14847

mongobleed-exploit-CVE-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

View Repository
132159 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🩸 MongoBleed - CVE-2025-14847 Security Research Lab

MongoBleed Logo

CVE-2025-14847 | CVSS 8.7 (High) | Unauthenticated Memory Disclosure

📖 Full Documentation • 🔬 Technical Analysis • ⚡ Quick Commands


🎯 CVE-2025-14847 Summary

MongoBleed is a critical memory disclosure vulnerability in MongoDB's network transport layer that allows unauthenticated remote attackers to exfiltrate sensitive heap memory without any credentials or user interaction.

Impact

CategoryDescription
Attack TypeRemote, unauthenticated memory disclosure
Root CauseZlib decompression returns allocated buffer size instead of actual data length
Data ExposedDatabase passwords, API keys, session tokens, AWS credentials, internal server state
SeverityCVSS 8.7 (High) - Network-accessible, no auth required
ExploitationActive exploitation observed in the wild since Dec 28, 2025

Vulnerable Versions (At a Glance)

BranchVulnerableFixedAction
8.2.x8.2.0 → 8.2.28.2.3Upgrade immediately
8.0.x8.0.0 → 8.0.168.0.17Upgrade immediately
7.0.x7.0.0 → 7.0.277.0.28Upgrade immediately
6.0.x6.0.0 → 6.0.266.0.27Upgrade immediately
5.0.x5.0.0 → 5.0.315.0.32Upgrade immediately
4.4.x4.4.0 → 4.4.294.4.30Upgrade immediately
≤4.2.xAll versionsNone⚠️ EOL - Migrate to supported version

📖 See Full Affected Versions Table →

Exposure Scale

  • 87,000 - 194,000 MongoDB instances publicly exposed
  • 42% of cloud environments host vulnerable instances (Wiz Research)
  • No authentication required - attack occurs pre-auth
  • Silent exploitation - no logs, no crashes

TL;DR for Engineering Teams

AspectDetails
What is vulnerableMongoDB Server network transport layer using zlib compression
SeverityHigh (CVSS 8.7/7.5)
ImpactUnauthenticated, remote disclosure of uninitialised heap memory
Why it mattersLeaked fragments contain database passwords, AWS secret keys, and internal server states
Exploit statusPublic Proof-of-Concept (PoC) "mongobleed" is validated and circulating
What to do todayUpgrade to patched versions immediately or disable zlib compression

🔬 Vulnerability Anatomy

Technical Analysis

The vulnerability exists in MongoDB's network transport layer (message_compressor_zlib.cpp) where a critical flaw in the zlib decompression logic allows unauthenticated attackers to leak sensitive server memory.

Root Cause

// VULNERABLE CODE (before fix)
counterHitDecompress(input.length(), output.length());
return {output.length()};  // ❌ Returns ALLOCATED buffer size

// PATCHED CODE (after fix)  
counterHitDecompress(input.length(), output.length());
return length;             // ✅ Returns ACTUAL decompressed data length

Exploitation Flow

┌─────────────────────────────────────────────────────────────────────────────┐
│                        MongoBleed Attack Vector                             │
├─────────────────────────────────────────────────────────────────────────────┤
│                                                                              │
│   ATTACKER                         VULNERABLE MongoDB                        │
│      │                                    │                                  │
│      │  1. Send OP_COMPRESSED message     │                                  │
│      │     uncompressedSize: 8192 (LIE)   │                                  │
│      │     actual data: ~100 bytes        │                                  │
│      │────────────────────────────────────>                                  │
│      │                                    │                                  │
│      │                          2. Allocate 8192-byte buffer                 │
│      │                          3. Decompress ~100 bytes                     │
│      │                          4. BUG: Return buffer.length() = 8192        │
│      │                          5. BSON parser reads uninitialized memory    │
│      │                                    │                                  │
│      │  6. Error response with leaked     │                                  │
│      │     memory as "field names"        │                                  │
│      │<────────────────────────────────────                                  │
│      │                                    │                                  │
│   🔓 LEAKED DATA:                         │                                  │
│      - API keys, passwords, tokens                                           │
│      - MongoDB internal state                                                │
│      - WiredTiger storage configs                                            │
│      - System /proc information                                              │
│      - Client connection data                                                │
│                                                                              │
└─────────────────────────────────────────────────────────────────────────────┘

Discovery Timeline

DateEvent
15 Dec 2025Vulnerability identified; internal ticket SERVER-115508
19 Dec 2025Fix released, CVE-2025-14847 disclosed
24 Dec 2025MongoDB Atlas fleet patched
26 Dec 2025Public PoC "mongobleed" released
28 Dec 2025Exploitation observed in the wild

🔬 See Technical Analysis → for detailed vulnerability anatomy, exploit construction, and detection methods.

📁 Project Structure

mongobleed-exploit-CVE-2025-14847/
├── exploit/                    # 🔴 Exploit Lab
│   ├── docker-compose.yml      # Vulnerable + Patched MongoDB instances
│   ├── mongobleed.py           # Memory leak exploit PoC
│   ├── init/init-mongo.js      # Sensitive test data
│   ├── test-exploit.sh         # Lab test script
│   └── README.md               # Lab documentation
│
├── scanner/                    # 🌐 Network Scanner
│   ├── mongobleed_scanner.py   # IP/domain vulnerability scanner
│   ├── sample-targets.txt      # Sample targets file
│   └── README.md               # Scanner documentation
│
├── code-scan/                  # 📂 Code Scanner
│   ├── main.py                 # CLI entry point
│   ├── scanners/               # Docker, Python, Infra scanners
│   ├── models/                 # Finding, Vulnerability models
│   ├── integrations/           # Phoenix Security upload
│   └── README.md               # Code scanner documentation
│
└── original-exploit/           # 📚 Original PoC reference

🚀 Quick Start

1. Exploit Lab

cd exploit

# Start lab (vulnerable + patched instances)
docker-compose up -d
sleep 10

# Test vulnerable instance (should leak memory)
python3 mongobleed.py --host localhost --port 27017
Download Tool