目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-14847— MongoDB Server 安全漏洞

一分钟漏洞结论

影响对象
MongoDB Inc. MongoDB Server
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server存在安全漏洞,该漏洞源于Zlib压缩协议头长度不匹配,可能导致读取未初始化内存。以下版本受到影响:v7.0 7.0.28之前版本、v8.0 8.0.17之前版本、v8.2 8.2.3之前版本、v6.0 6.0.27之前版本、v5.0 5.0.32之前版本、v4.4 4.4.30之前版本、v4.2 4.2.0及之后版本、v4.0

CVSS 7.5 · High KEV EPSS 83.22% · P100

公开利用映射 1

可能的 ATT&CK 技术 1 AI

T1552 · Unsecured Credentials
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-14847 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Zlib compressed protocol header length confusion may allow memory read
来源: CVE Program / CVE List V5
Vulnerability Description
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
长度参数不一致性处理不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
MongoDB Server 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server存在安全漏洞,该漏洞源于Zlib压缩协议头长度不匹配,可能导致读取未初始化内存。以下版本受到影响:v7.0 7.0.28之前版本、v8.0 8.0.17之前版本、v8.2 8.2.3之前版本、v6.0 6.0.27之前版本、v5.0 5.0.32之前版本、v4.4 4.4.30之前版本、v4.2 4.2.0及之后版本、v4.0
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
MongoDB Inc. MongoDB Server 8.2 ~ 8.2.3 -

二、漏洞 CVE-2025-14847 的公开POC

# POC 描述 源链接 神龙链接
1 MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具 https://github.com/onewinner/CVE-2025-14847 POC详情
2 poc for CVE-2025-14847 https://github.com/ProbiusOfficial/CVE-2025-14847 POC详情
3 a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnerable MongoDB instances. https://github.com/cybertechajju/CVE-2025-14847_Expolit POC详情
4 None https://github.com/KingHacker353/CVE-2025-14847_Expolit POC详情
5 CVE-2025-14847 https://github.com/Ashwesker/Blackash-CVE-2025-14847 POC详情
6 MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool https://github.com/Black1hp/mongobleed-scanner POC详情
7 golang test tool for mongobleed (cve-2025-14847) https://github.com/nma-io/mongobleed POC详情
8 None https://github.com/saereya/CVE-2025-14847---MongoBleed POC详情
9 The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation. https://github.com/JemHadar/MongoBleed-DFIR-Triage-Script-CVE-2025-14847 POC详情
10 Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader https://github.com/franksec42/mongobleed-exploit-CVE-2025-14847 POC详情
11 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2025/CVE-2025-14847.yaml POC详情
12 CVE-2025-14847 https://github.com/Ashwesker/Ashwesker-CVE-2025-14847 POC详情
13 CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit https://github.com/lincemorado97/CVE-2025-14847 POC详情
14 Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools https://github.com/Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847 POC详情
15 Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research. https://github.com/chinaxploiter/CVE-2025-14847-PoC POC详情
16 Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner https://github.com/14mb1v45h/CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 POC详情
17 MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool https://github.com/kuyrathdaro/cve-2025-14847 POC详情
18 CVE-2025-14847 (MongoBleed) https://github.com/joshuavanderpoll/CVE-2025-14847 POC详情
19 Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847. https://github.com/tunahantekeoglu/MongoDeepDive POC详情
20 Remake of CVE-2025-14847 MongoDB vulnerability demonstration https://github.com/vfa-tuannt/CVE-2025-14847 POC详情
21 Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab. https://github.com/j0lt-github/mongobleedburp POC详情
22 CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC https://github.com/FurkanKAYAPINAR/CVE-2025-14847-MongoBleed-Exploit POC详情
23 This repo contains my python script version of CVE-2025-14847 (MongoBleed) https://github.com/NoNameError/MongoBLEED---CVE-2025-14847-POC- POC详情
24 None https://github.com/Rishi-kaul/CVE-2025-14847-MongoBleed POC详情
25 MongoBleed CVE-2025-14847 Vulnerability Checker https://github.com/Systemhaus-Schulz/MongoBleed-CVE-2025-14847 POC详情
26 CVE-2025-14847 exploit for MongoDB heap memory disclosure https://github.com/demetriusford/mongobleed POC详情
27 MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes a vulnerable Docker container with multi-database seeding (PII, API keys) and a Python exploit to demonstrate data extraction. Ideal for security research and awareness. 1-day analysis. https://github.com/ElJoamy/MongoBleed-exploit POC详情
28 Mongobleed Detector CVE-2025-14847 https://github.com/keraattin/Mongobleed-Detector-CVE-2025-14847 POC详情
29 CVE-2025-14847 MongoDB Memory Leak Exploit https://github.com/waheeb71/CVE-2025-14847 POC详情
30 Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit. https://github.com/CadGoose/MongoBleed-CVE-2025-14847-Fully-Automated-scanner POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-14847 的情报信息

登录查看更多情报信息。

CVE-2025-14847 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-14847

暂无评论


发表评论