Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-14847 — CVE-2025-14847 MongoDB Memory Leak Exploit | Kitploit
Tools/GitHubGitHub/waheeb71/cve-2025-14847
Memory ForensicsVulnerability AnalysisExploitationPenetration TestingLearning & EducationDatabase Security
GitHubwaheeb71/cve-2025-14847

CVE-2025-14847

CVE-2025-14847 MongoDB Memory Leak Exploit

View Repository
1178 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

mongoExploit (CVE-2025-14847)

mongoExploit is a Proof-of-Concept (PoC) exploit tool for CVE-2025-14847, a memory leak vulnerability in MongoDB.

This tool exploits a bug in zlib decompression to leak server memory via BSON field names. By crafting a BSON payload with an inflated document length, it forces the server to read field names from leaked memory until a null byte is encountered.

⚠️ Disclaimer

This tool is for educational and authorized security testing purposes only. The author is not responsible for any misuse of this tool. Do not use this against systems you do not have explicit permission to test.

Features

  • Scans a range of offsets to leak memory fragments.
  • Saves leaked data to a binary file.
  • Automatic detection of potential secrets (passwords, keys, tokens).
  • Customizable scan range and buffer sizes.

Requirements

  • Python 3.x

Usage

python3 mongoExploit.py [options]

Arguments

ArgumentDescriptionDefault
--hostTarget host IP or hostnamelocalhost
--portTarget MongoDB port27017
--min-offsetMinimum document length (offset start)20
--max-offsetMaximum document length (offset end)8192
--outputOutput file for leaked dataleaked.bin

Examples

Basic Scan

Scan specific target with default settings:

python3 mongoExploit.py --host 192.168.1.10

Deep Scan

Scan for more data with a larger offset range:

python3 mongoExploit.py --host 192.168.1.10 --max-offset 50000

Custom Range

Scan a specific range of offsets:

python3 mongoExploit.py --host 192.168.1.10 --min-offset 100 --max-offset 20000

Output

The tool displays interesting leaks (strings > 10 chars) in the console and saves all collected unique fragments to the specified output file (default: leaked.bin).

It also attempts to highlight patterns resembling secrets such as:

  • password
  • secret
  • key
  • token
  • admin
  • AKIA (AWS Keys)

References

  • CVE-2025-14847
Download Tool