CVE-2025-14847CISA KEV: Actively Exploited

MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

Published Dec 29, 2025·Updated Dec 29, 2025

Description

MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.

Public Exploits & PoCs39 found

PoC: CVE-2025-14847

poc for CVE-2025-14847

5

PoC: CVE-2025-14847_Expolit

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnerable MongoDB instances.

4

PoC: azure-vulnerability-remediation-project

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to mitigate CVE-2025-14847.

1

PoC: mongobleed

CVE-2025-14847 explaination and lab

1

PoC: CVE-2025-14847-MongoDB

CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC

1

PoC: CVE-2025-14847

CVE-2025-14847 (MongoBleed)

1

PoC: CVE-2025-14847

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

1

PoC: CVE-2025-14847-mongobleed

CVE-2025-14847 mongobleed python file

PoC: CVE-2025-14847

CVE-2025-14847

PoC: MongoBleed

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction, credential parsing, CIDR/batch scanning, Nuclei templates, and CTF lab included

PoC: CVE-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

PoC: sakthivel10q.github.io

🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.

PoC: pedrocruz2202.github.io

🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data protection.

PoC: mongobleed-scanner

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently.

PoC: CVE-2025-14847

CVE-2025-14847 | MongoBleed vulnerability proof of concept project

PoC: mongobleed

CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

PoC: MongoBleed-CVE-2025-14847-Fully-Automated-scanner

Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.

PoC: CVE-2025-14847

CVE-2025-14847 MongoDB Memory Leak Exploit

PoC: Mongobleed-Detector-CVE-2025-14847

Mongobleed Detector CVE-2025-14847

PoC: MongoBleed-exploit

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes a vulnerable Docker container with multi-database seeding (PII, API keys) and a Python exploit to demonstrate data extraction. Ideal for security research and awareness. 1-day analysis.

PoC: mongobleed

CVE-2025-14847

PoC: MongoBleed-CVE-2025-14847

MongoBleed CVE-2025-14847 Vulnerability Checker

PoC: MongoBLEED---CVE-2025-14847-POC-

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

PoC: mongobleedburp

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.

PoC: CVE-2025-14847

Remake of CVE-2025-14847 MongoDB vulnerability demonstration

PoC: MongoDeepDive

Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.

PoC: mongobleeder

A proof-of-concept exploit for CVE-2025-14847, a critical memory leak vulnerability in MongoDB's OP_COMPRESSED message handler.

PoC: cve-2025-14847

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

PoC: CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

PoC: CVE-2025-14847-PoC

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

PoC: mongobleed-exploit-CVE-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

PoC: cve-2025-14847

MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool

PoC: CVE-2025-14847

CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit

PoC: mongobleed-exploit-CVE-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

PoC: MongoBleed-DFIR-Triage-Script-CVE-2025-14847-

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation.

PoC: mongobleed

golang test tool for mongobleed (cve-2025-14847)

PoC: mongobleed-scanner

MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool

PoC: Blackash-CVE-2025-14847

CVE-2025-14847

PoC: CVE-2025-14847

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free