NOMISEC-NoNameError/MongoBLEED---CVE-2025-14847-POC-

NOMISEC WORKING POC
Exploit for CVE-2025-14847 - MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
AI Analysis

This PoC exploits CVE-2025-14847 (MongoBLEED) by sending a maliciously crafted OP_COMPRESSED packet to trigger a heap memory leak in MongoDB. The script forges a decompression size field to leak adjacent heap memory, demonstrating the vulnerability.

Attack Type
info_leak
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1059 - Command and Scripting Interpreter T1040 - Network Sniffing
Loading exploit code...
Download ZIP Password: eip
Source
Platform Nomisec
Type remote
Files 2
Stars 1
Forks 0
Last Push Dec 30, 2025
Authors
NoNameError F1D0
Vulnerability
CVE-2025-14847
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
HIGH KEV
CVSS 7.5