{"repo":"Black1hp/mongobleed-scanner","free":true,"listed":false,"github":"https://github.com/Black1hp/mongobleed-scanner","clone":"git clone https://github.com/Black1hp/mongobleed-scanner.git","description":"MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool","language":"Python","stars":35,"topics":["bug-bounty","mongodb","penetration-testing","red-team","zlib","cve-2025-14847","heap-memory-leak","info-disclosure","mongodb-exploit","mongodb-security"],"license":null,"category":"security-tools","readme_excerpt":"MongoBleed (CVE-2025-14847) MongoBleed is a high-performance PoC scanner for CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability in the MongoDB C++ Driver. The tool is designed for rapid identification of vulnerable instances across large network ranges. Technical Analysis The vulnerability stems from an out-of-bounds (OOB) read in the MongoDB wire protocol’s handling of OP COMPRESSED messages. When a server receives an OP COMPRESSED packet, it relies on the attacker-supplied uncompressedSize field to allocate a buffer for decompression. If the actual decompressed data is significantly smaller than the claimed uncompressedSize , the driver fails to truncate or clear the buffer. As a result, the server returns the entire allocated memory block, which may contain uninitialized heap data, potentially exposing sensitive information such as session tokens, internal pointers, or fragments of other database queries. Features Asynchronous I/O using Python asyncio for high-concurrency scanning Precise detection by validating response length against the requested leak size Minimal false positives through verified protocol-level interaction Automatic logging of vulnerable targets to vulnerable targets.txt Installation No external dependencies required (Python Standard Library only). Usage Basic usage: Advanced configuration: Options -i : Input file containing targets (IP, domain, or IP:port) -c : Concurrency level (default: 50) -t : Connection timeout in seconds (d","default_branch":null,"files":null,"tree":[],"storefront":"/r/Black1hp","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Black1hp/mongobleed-scanner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}