# Zlib协议头长度混淆漏洞
## 概述
在 Zlib 压缩协议头部中,由于长度字段不匹配,可能导致未认证客户端读取未初始化的堆内存。
## 影响版本
- MongoDB Server v7.0:低于 7.0.28
- MongoDB Server v8.0:低于 8.0.17
- MongoDB Server v8.2:低于 8.2.3
- MongoDB Server v6.0:低于 6.0.27
- MongoDB Server v5.0:低于 5.0.32
- MongoDB Server v4.4:低于 4.4.30
- MongoDB Server v4.2:≥ 4.2.0
- MongoDB Server v4.0:≥ 4.0.0
- MongoDB Server v3.6:≥ 3.6.0
## 细节
当解析 Zlib 压缩的协议头部时,若长度字段存在不匹配的情况,可能触发越界读取,从而访问未初始化的堆内存。
## 影响
未认证攻击者可利用此漏洞读取服务器上的未初始化堆内存,可能造成信息泄露。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具 | https://github.com/onewinner/CVE-2025-14847 | POC详情 |
| 2 | poc for CVE-2025-14847 | https://github.com/ProbiusOfficial/CVE-2025-14847 | POC详情 |
| 3 | a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnerable MongoDB instances. | https://github.com/cybertechajju/CVE-2025-14847_Expolit | POC详情 |
| 4 | None | https://github.com/KingHacker353/CVE-2025-14847_Expolit | POC详情 |
| 5 | CVE-2025-14847 | https://github.com/Ashwesker/Blackash-CVE-2025-14847 | POC详情 |
| 6 | MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool | https://github.com/Black1hp/mongobleed-scanner | POC详情 |
| 7 | golang test tool for mongobleed (cve-2025-14847) | https://github.com/nma-io/mongobleed | POC详情 |
| 8 | None | https://github.com/saereya/CVE-2025-14847---MongoBleed | POC详情 |
| 9 | The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation. | https://github.com/JemHadar/MongoBleed-DFIR-Triage-Script-CVE-2025-14847 | POC详情 |
| 10 | Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader | https://github.com/franksec42/mongobleed-exploit-CVE-2025-14847 | POC详情 |
| 11 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2025/CVE-2025-14847.yaml | POC详情 |
| 12 | CVE-2025-14847 | https://github.com/Ashwesker/Ashwesker-CVE-2025-14847 | POC详情 |
| 13 | CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit | https://github.com/lincemorado97/CVE-2025-14847 | POC详情 |
| 14 | Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools | https://github.com/Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847 | POC详情 |
| 15 | Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research. | https://github.com/chinaxploiter/CVE-2025-14847-PoC | POC详情 |
| 16 | Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner | https://github.com/14mb1v45h/CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 | POC详情 |
| 17 | MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool | https://github.com/kuyrathdaro/cve-2025-14847 | POC详情 |
| 18 | CVE-2025-14847 (MongoBleed) | https://github.com/joshuavanderpoll/CVE-2025-14847 | POC详情 |
| 19 | Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847. | https://github.com/tunahantekeoglu/MongoDeepDive | POC详情 |
| 20 | Remake of CVE-2025-14847 MongoDB vulnerability demonstration | https://github.com/vfa-tuannt/CVE-2025-14847 | POC详情 |
| 21 | Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab. | https://github.com/j0lt-github/mongobleedburp | POC详情 |
| 22 | CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC | https://github.com/FurkanKAYAPINAR/CVE-2025-14847-MongoBleed-Exploit | POC详情 |
| 23 | This repo contains my python script version of CVE-2025-14847 (MongoBleed) | https://github.com/NoNameError/MongoBLEED---CVE-2025-14847-POC- | POC详情 |
| 24 | None | https://github.com/Rishi-kaul/CVE-2025-14847-MongoBleed | POC详情 |
| 25 | MongoBleed CVE-2025-14847 Vulnerability Checker | https://github.com/Systemhaus-Schulz/MongoBleed-CVE-2025-14847 | POC详情 |
| 26 | CVE-2025-14847 exploit for MongoDB heap memory disclosure | https://github.com/demetriusford/mongobleed | POC详情 |
| 27 | MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes a vulnerable Docker container with multi-database seeding (PII, API keys) and a Python exploit to demonstrate data extraction. Ideal for security research and awareness. 1-day analysis. | https://github.com/ElJoamy/MongoBleed-exploit | POC详情 |
| 28 | Mongobleed Detector CVE-2025-14847 | https://github.com/keraattin/Mongobleed-Detector-CVE-2025-14847 | POC详情 |
| 29 | CVE-2025-14847 MongoDB Memory Leak Exploit | https://github.com/waheeb71/CVE-2025-14847 | POC详情 |
| 30 | Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit. | https://github.com/CadGoose/MongoBleed-CVE-2025-14847-Fully-Automated-scanner | POC详情 |
| 31 | CVE-2025-14847 explaination and lab | https://github.com/AdolfBharath/mongobleed | POC详情 |
| 32 | None | https://github.com/sahar042/CVE-2025-14847 | POC详情 |
| 33 | CVE-2025-14847 | MongoBleed vulnerability proof of concept project | https://github.com/peakcyber-security/CVE-2025-14847 | POC详情 |
| 34 | None | https://github.com/alexcyberx/CVE-2025-14847_Expolit | POC详情 |
| 35 | 🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data. | https://github.com/sakthivel10q/CVE-2025-14847 | POC详情 |
| 36 | 🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently. | https://github.com/pedrocruz2202/mongobleed-scanner | POC详情 |
| 37 | 🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data protection. | https://github.com/pedrocruz2202/pedrocruz2202.github.io | POC详情 |
| 38 | 🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output. | https://github.com/sakthivel10q/sakthivel10q.github.io | POC详情 |
| 39 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E6%95%B0%E6%8D%AE%E5%BA%93%E6%BC%8F%E6%B4%9E/MongoDB%20Zlib%20%E5%8E%8B%E7%BC%A9%E5%8D%8F%E8%AE%AE%E5%A0%86%E5%86%85%E5%AD%98%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E%20CVE-2025-14847.md | POC详情 |
暂无评论