Repository navigation
Update dependency pymongo to v4.18.2 [SECURITY] - #487
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
renovate
Bot
force-pushed
the
renovate/pypi-pymongo-vulnerability
branch
from
October 7, 2026 09:34
df9d697 to
73ad77d
Compare
|
renovate
Bot
force-pushed
the
renovate/pypi-pymongo-vulnerability
branch
from
October 8, 2026 13:24
73ad77d to
c0c2a7a
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.17.0→4.18.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
CVE-2026-88029 / GHSA-8fvv-fgr5-f8ch
More information
Details
Impact
When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match.
Patches
Patch available in pymongo >= 4.18.1
Workarounds
Ensure your existing workflow only supports exact matching on the GridFS API.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
CVE-2026-96747 / GHSA-qx36-8mw2-4r3x
More information
Details
Summary
PyMongo passed the KMS endpoint of a data key verbatim into
parse_host(), which returns any string ending in.sockunchanged instead of validating it as a hostname and port. The driver's connection code then treats such an address as a Unix domain socket path and connects to it withAF_UNIX. Because the endpoint originates frommasterKey.endpointin a key vault document, a party who can write to the key vault could redirect the driver's KMS connection to an arbitrary Unix domain socket path on the application host.Impact
An application using client-side field level encryption (CSFLE) or Queryable Encryption is affected if an attacker can write to its key vault collection. Setting
masterKey.endpointon a data key to a.sock-suffixed string causes the next KMS request for that key (key cache TTL is ~60 seconds) to open anAF_UNIXconnection to the attacker-chosen filesystem path from inside the victim application process. The documented custom KMS endpoint feature supports TCP hosts only, so this crosses a boundary the feature was never intended to allow.Impact is limited to the side effects of the connection itself. The socket is still wrapped in a verifying TLS context using the
.sockstring asserver_hostname, and insecure KMS TLS options are rejected, so the handshake always fails and the KMS message is never sent. The attacker controls the connect target but not the transmitted bytes (a fixed TLS ClientHello).Applications that do not use CSFLE or Queryable Encryption are not affected. Applications whose key vault is not writable by untrusted parties are not affected.
Patches
Fixed in PyMongo 4.18.2
_EncryptionIO.kms_requestnow rejects a.sock-suffixed KMS endpoint withpymongo.errors.ConfigurationErrorimmediately after parsing, before any connection is attempted, on both the synchronous and asynchronous paths. No application code changes are required beyond upgrading.Workarounds
If you cannot upgrade immediately:
masterKey.endpointon data keys you create, and audit existing key vault documents for endpoints ending in.sock.Details
_EncryptionIO.fetch_keysreads key vault documents from the server and hands them to libmongocrypt, which surfaces the storedmasterKey.endpointverbatim askms_context.endpoint._EncryptionIO.kms_requestpassed that string toparse_host(endpoint, 443).parse_hostreturns entities ending in.sockverbatim, skipping the hostname and port validation applied to every other input._create_connection(and the async equivalent) checkshost.endswith(".sock")and performs anAF_UNIXsock.connect(host), treating the string as a filesystem path.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
CVE-2026-96748 / GHSA-vp6j-j7w5-5xjj
More information
Details
Summary
PyMongo percent-decoded the entire host section of a connection string before splitting it into individual
host:portentries. A percent-encoded,or:in a hostname therefore decoded into a real delimiter, injecting an additional attacker-chosen host and port into the client's seed list.Impact
An application that interpolates untrusted input into a MongoDB connection string -- for example, a tenant name or hostname fragment taken from a request -- could be made to add an attacker-controlled server to the seed list. Because
%2Cand%3Asurvive most URL-safety checks and only become delimiters inside PyMongo's parser, input that looks like a single hostname to the application becomes two hosts to the driver. The client may then perform topology discovery and authentication against the attacker's host, exposing credentials, or route operations to it.Unix domain socket paths, the only host identifiers that legitimately require percent-encoding, are not affected.
Patches
Fixed in PyMongo 4.18.2. Percent-decoding was moved into
split_hostsand now applies only to Unix domain socket paths, identified by an unescaped.socksuffix before decoding, and only after splitting on,.Workarounds
Do not interpolate untrusted input into the host portion of a connection string. If unavoidable, reject or percent-decode-and-validate the value before building the URI.
Details
The decoding was introduced in PyMongo 3.5.0 (PYTHON-1282), where
unquote_pluswas applied to the whole host section in_validate_uriand, later,_parse_srv, before the string was split on,and:.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-96749 / GHSA-v4x9-3549-crwv
More information
Details
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mongodb/mongo-python-driver (pymongo)
v4.18.2: PyMongo 4.18.2Compare Source
Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732
CVE-2026-96749
CVE-2026-96748
CVE-2026-96747
v4.18.1: PyMongo 4.18.1Compare Source
Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-1-released/343338
v4.18.0: PyMongo 4.18.0Compare Source
Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-released/343137
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.