CVE-2025-14847

HIGH KEV NUCLEI

MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed

Title source: metasploit

Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Exploits (45)

nomisec WORKING POC 34 stars
by Black1hp · poc
https://github.com/Black1hp/mongobleed-scanner
nomisec WORKING POC 25 stars
by cybertechajju · infoleak
https://github.com/cybertechajju/CVE-2025-14847_Expolit
nomisec WORKING POC 24 stars
by ProbiusOfficial · infoleak
https://github.com/ProbiusOfficial/CVE-2025-14847
nomisec SCANNER 11 stars
by onewinner · infoleak
https://github.com/onewinner/CVE-2025-14847
nomisec WORKING POC 9 stars
by Security-Phoenix-demo · infoleak
https://github.com/Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847
nomisec SUSPICIOUS 4 stars
by chinaxploiter · poc
https://github.com/chinaxploiter/CVE-2025-14847-PoC
github WORKING POC 4 stars
by ctkqiang · gopoc
https://github.com/ctkqiang/CVE-Exploits/tree/main/CVE-2025-14847
nomisec WORKING POC 3 stars
by joshuavanderpoll · infoleak
https://github.com/joshuavanderpoll/CVE-2025-14847
nomisec WORKING POC 2 stars
by franksec42 · infoleak
https://github.com/franksec42/mongobleed-exploit-CVE-2025-14847
nomisec WORKING POC 2 stars
by nma-io · infoleak
https://github.com/nma-io/mongobleed
nomisec WORKING POC 2 stars
by alexcyberx · infoleak
https://github.com/alexcyberx/CVE-2025-14847_Expolit
nomisec WORKING POC 1 stars
by waheeb71 · infoleak
https://github.com/waheeb71/CVE-2025-14847
nomisec WORKING POC 1 stars
by sho-luv · infoleak
https://github.com/sho-luv/MongoBleed
nomisec WORKING POC 1 stars
by FurkanKAYAPINAR · poc
https://github.com/FurkanKAYAPINAR/CVE-2025-14847-MongoBleed-Exploit
nomisec WRITEUP 1 stars
by AdolfBharath · infoleak
https://github.com/AdolfBharath/mongobleed
nomisec WORKING POC 1 stars
by NoNameError · remote
https://github.com/NoNameError/MongoBLEED---CVE-2025-14847-POC-
nomisec WORKING POC 1 stars
by InfoSecAntara · poc
https://github.com/InfoSecAntara/CVE-2025-14847-MongoDB
nomisec WORKING POC 1 stars
by lincemorado97 · infoleak
https://github.com/lincemorado97/CVE-2025-14847
nomisec WORKING POC 1 stars
by peakcyber-security · infoleak
https://github.com/peakcyber-security/CVE-2025-14847
nomisec WORKING POC
by 14mb1v45h · poc
https://github.com/14mb1v45h/CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026
nomisec SCANNER
by pedrocruz2202 · poc
https://github.com/pedrocruz2202/mongobleed-scanner
nomisec WORKING POC
by tunahantekeoglu · poc
https://github.com/tunahantekeoglu/MongoDeepDive
nomisec WORKING POC
by ElJoamy · poc
https://github.com/ElJoamy/MongoBleed-exploit
nomisec WRITEUP
by Rishi-kaul · poc
https://github.com/Rishi-kaul/CVE-2025-14847-MongoBleed
nomisec WRITEUP
by JemHadar · poc
https://github.com/JemHadar/MongoBleed-DFIR-Triage-Script-CVE-2025-14847
nomisec SCANNER
by keraattin · poc
https://github.com/keraattin/Mongobleed-Detector-CVE-2025-14847
nomisec WRITEUP
by zaryouhashraf · poc
https://github.com/zaryouhashraf/CVE-2025-14847
nomisec WORKING POC
by sakthivel10q · infoleak
https://github.com/sakthivel10q/CVE-2025-14847
nomisec WORKING POC
by KingHacker353 · infoleak
https://github.com/KingHacker353/CVE-2025-14847_Expolit
nomisec WORKING POC
by saereya · infoleak
https://github.com/saereya/CVE-2025-14847---MongoBleed
nomisec WORKING POC
by kuyrathdaro · infoleak
https://github.com/kuyrathdaro/cve-2025-14847
nomisec WORKING POC
by vfa-tuannt · infoleak
https://github.com/vfa-tuannt/CVE-2025-14847
nomisec SCANNER
by Systemhaus-Schulz · infoleak
https://github.com/Systemhaus-Schulz/MongoBleed-CVE-2025-14847
nomisec SCANNER
by CadGoose · infoleak
https://github.com/CadGoose/MongoBleed-CVE-2025-14847-Fully-Automated-scanner
nomisec WORKING POC
by im-hanzou · infoleak
https://github.com/im-hanzou/mongobleed
nomisec WORKING POC
by sahar042 · infoleak
https://github.com/sahar042/CVE-2025-14847
nomisec SCANNER
by amnnrth · infoleak
https://github.com/amnnrth/CVE-2025-14847
nomisec WORKING POC
by j0lt-github · infoleak
https://github.com/j0lt-github/mongobleedburp
nomisec SUSPICIOUS
by sakthivel10q · poc
https://github.com/sakthivel10q/sakthivel10q.github.io
nomisec SUSPICIOUS
by pedrocruz2202 · poc
https://github.com/pedrocruz2202/pedrocruz2202.github.io
nomisec WRITEUP
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2025-14847
metasploit WORKING POC
by Alexander Hagenah, Diego Ledda, Joe Desimone · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/mongodb/cve_2025_14847_mongobleed.rb
vulncheck_xdb WORKING POC
infoleak
https://github.com/FurkanKAYAPINAR/CVE-2025-14847-MongoDB

Nuclei Templates (1)

MongoDB Server - Information Disclosure (MongoBleed)
HIGHVERIFIEDby pussycat0x,joe-desimone,DhiyaneshDK

Scores

CVSS v3 7.5
EPSS 0.6885
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

CISA KEV 2025-12-29
VulnCheck KEV 2025-12-28
ENISA EUVD EUVD-2025-204529

Classification

CWE
CWE-130
Status published

Affected Products (2)

mongodb/mongodb < 4.4.30
mongodb/mongodb < 6.0.27

Timeline

Published Dec 19, 2025
KEV Added Dec 29, 2025
Tracked Since Feb 18, 2026