Skip to content

Update dependency pymongo to v4.18.2 [SECURITY] - #487

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pymongo-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pymongo-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
pymongo 4.17.0 → 4.18.2 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods

CVE-2026-88029 / GHSA-8fvv-fgr5-f8ch

More information

Details

Impact

When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match.

Patches

Patch available in pymongo >= 4.18.1

Workarounds

Ensure your existing workflow only supports exact matching on the GridFS API.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption

CVE-2026-96747 / GHSA-qx36-8mw2-4r3x

More information

Details

Summary

PyMongo passed the KMS endpoint of a data key verbatim into parse_host(), which returns any string ending in .sock unchanged instead of validating it as a hostname and port. The driver's connection code then treats such an address as a Unix domain socket path and connects to it with AF_UNIX. Because the endpoint originates from masterKey.endpoint in a key vault document, a party who can write to the key vault could redirect the driver's KMS connection to an arbitrary Unix domain socket path on the application host.

Impact

An application using client-side field level encryption (CSFLE) or Queryable Encryption is affected if an attacker can write to its key vault collection. Setting masterKey.endpoint on a data key to a .sock-suffixed string causes the next KMS request for that key (key cache TTL is ~60 seconds) to open an AF_UNIX connection to the attacker-chosen filesystem path from inside the victim application process. The documented custom KMS endpoint feature supports TCP hosts only, so this crosses a boundary the feature was never intended to allow.

Impact is limited to the side effects of the connection itself. The socket is still wrapped in a verifying TLS context using the .sock string as server_hostname, and insecure KMS TLS options are rejected, so the handshake always fails and the KMS message is never sent. The attacker controls the connect target but not the transmitted bytes (a fixed TLS ClientHello).

Applications that do not use CSFLE or Queryable Encryption are not affected. Applications whose key vault is not writable by untrusted parties are not affected.

Patches

Fixed in PyMongo 4.18.2 _EncryptionIO.kms_request now rejects a .sock-suffixed KMS endpoint with pymongo.errors.ConfigurationError immediately after parsing, before any connection is attempted, on both the synchronous and asynchronous paths. No application code changes are required beyond upgrading.

Workarounds

If you cannot upgrade immediately:

  • Restrict write access to the key vault collection to trusted principals only. This is the recommended configuration regardless of this issue.
  • Validate masterKey.endpoint on data keys you create, and audit existing key vault documents for endpoints ending in .sock.
Details
  • _EncryptionIO.fetch_keys reads key vault documents from the server and hands them to libmongocrypt, which surfaces the stored masterKey.endpoint verbatim as kms_context.endpoint.
  • _EncryptionIO.kms_request passed that string to parse_host(endpoint, 443). parse_host returns entities ending in .sock verbatim, skipping the hostname and port validation applied to every other input.
  • _create_connection (and the async equivalent) checks host.endswith(".sock") and performs an AF_UNIX sock.connect(host), treating the string as a filesystem path.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters

CVE-2026-96748 / GHSA-vp6j-j7w5-5xjj

More information

Details

Summary

PyMongo percent-decoded the entire host section of a connection string before splitting it into individual host:port entries. A percent-encoded , or : in a hostname therefore decoded into a real delimiter, injecting an additional attacker-chosen host and port into the client's seed list.

Impact

An application that interpolates untrusted input into a MongoDB connection string -- for example, a tenant name or hostname fragment taken from a request -- could be made to add an attacker-controlled server to the seed list. Because %2C and %3A survive most URL-safety checks and only become delimiters inside PyMongo's parser, input that looks like a single hostname to the application becomes two hosts to the driver. The client may then perform topology discovery and authentication against the attacker's host, exposing credentials, or route operations to it.

Unix domain socket paths, the only host identifiers that legitimately require percent-encoding, are not affected.

Patches

Fixed in PyMongo 4.18.2. Percent-decoding was moved into split_hosts and now applies only to Unix domain socket paths, identified by an unescaped .sock suffix before decoding, and only after splitting on ,.

Workarounds

Do not interpolate untrusted input into the host portion of a connection string. If unavoidable, reject or percent-decode-and-validate the value before building the URI.

Details

The decoding was introduced in PyMongo 3.5.0 (PYTHON-1282), where unquote_plus was applied to the whole host section in _validate_uri and, later, _parse_srv, before the string was split on , and :.

Severity

  • CVSS Score: 8.3 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding

CVE-2026-96749 / GHSA-v4x9-3549-crwv

More information

Details

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

mongodb/mongo-python-driver (pymongo)

v4.18.2: PyMongo 4.18.2

Compare Source

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732

CVE-2026-96749
CVE-2026-96748
CVE-2026-96747

v4.18.1: PyMongo 4.18.1

Compare Source

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-1-released/343338

v4.18.0: PyMongo 4.18.0

Compare Source

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-released/343137


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Coverage

Converter - python code coverage
FileStmtsMissBranchBrPartCoverMissing
constants.py9000100% 
conversion_mixin.py2912194%25->26, 26
converter.py91512194%31->32, 32–33, 116, 127–128
database.py3734288%24->25, 25–26, 46->48, 66
logging_config.py46410388%33->34, 34–35, 41->42, 42, 48->49, 49
mongodb_monitoring.py17040100% 
tracing.py4596180%59–60, 66->70, 70, 76–78, 80–82
utils.py176574696%61–62, 77->78, 78, 85->84, 90->exit, 128->129, 129, 140->141, 141, 206->209
cisu_transcoders
   base_cisu_converter.py3330091%7, 25, 31
   constants.py5000100% 
   identical_cisu_converter.py9000100% 
   utils.py15060100% 
cisu_transcoders/create_case
   create_case_cisu_constants.py39000100% 
   create_case_cisu_converter.py215244298%159->162, 162, 277->278, 278
cisu_transcoders/reference
   reference_cisu_constants.py2000100% 
   reference_converter.py17000100% 
cisu_transcoders/resources_info
   resources_info_cisu_constants.py12000100% 
   resources_info_cisu_converter.py171332397%174->175, 175, 200->201, 201, 388->389, 389
   resources_info_cisu_helper.py49318293%57->58, 58, 62->63, 63, 66
cisu_transcoders/resources_status
   resources_status_constants.py4000100% 
   resources_status_converter.py4114098%33
cisu_version_converters
   base_cisu_version_converter.py2824191%9, 55->61, 61
   identical_cisu_version_converter.py9000100% 
cisu_version_converters/create_case
   create_case_version_converter.py40040100% 
cisu_version_converters/reference
   reference_version_converter.py14000100% 
cisu_version_converters/resources_info_cisu
   resources_info_cisu_version_converter.py510080%9
conversion_strategy
   cisu_transcoding_strategy.py49222294%51->72, 72, 96->97, 97
   cisu_version_conversion_strategy.py2328287%36->37, 37, 38->39, 39
   conversion_strategy.py1516190%30->36, 36
   health_version_conversion_strategy.py460240100% 
health_version_converters
   base_message_converter.py831214286%13, 72–74, 83->86, 86, 95->98, 98, 102, 106, 110, 114, 118, 124
   error_converter.py510080%9
   identical_message_converter.py15000100% 
   utils.py26512282%32->34, 34–37, 41->43, 43
health_version_converters/create_case_health
   constants.py4000100% 
   create_case_health_converter.py1780800100% 
   create_case_health_update_converter.py5000100% 
health_version_converters/create_case_health/v1_v2
   constants.py17000100% 
   utils.py46022297%36->34, 59->exit
health_version_converters/create_case_health/v2_v3
   constants.py29000100% 
health_version_converters/geo_positions_update
   geo_positions_update_constants.py4000100% 
   geo_positions_update_converter.py49312489%30->33, 33, 43->44, 44, 69->73, 80->81, 81
health_version_converters/geo_resources_details
   geo_resources_details_constants.py4000100% 
   geo_resources_details_converter.py27040100% 
health_version_converters/reference
   reference_constants.py2000100% 
   reference_converter.py13000100% 
health_version_converters/resources_engagement
   resources_engagement_constants.py3000100% 
   resources_engagement_converter.py2202196%33->40
health_version_converters/resources_info
   resources_info_constants.py20000100% 
   resources_info_converter.py87036398%119->156, 171->exit, 210->233
health_version_converters/resources_request
   resources_request_constants.py2000100% 
   resources_request_converter.py21000100% 
health_version_converters/resources_response
   resources_response_constants.py4000100% 
   resources_response_converter.py16020100% 
health_version_converters/resources_status
   resources_status_constants.py10000100% 
   resources_status_converter.py39000100% 
models
   persisted_message.py13000100% 
nomenclatures
   utils.py260140100% 
nomenclatures/from_v1_9_to_v2_3
   health_motive.py1000100% 
   location_kind.py1000100% 
   risk_threat.py1000100% 
   whats_happen.py1000100% 
nomenclatures/from_v2_3_to_v1_9
   health_motive.py1000100% 
   location_kind.py1000100% 
   risk_threat.py1000100% 
   whats_happen.py1000100% 
repositories
   message_repository.py701212283%90–91, 98, 118–120, 122–123, 125, 171–173
TOTAL2139804944395% 

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

@renovate
renovate Bot force-pushed the renovate/pypi-pymongo-vulnerability branch from df9d697 to 73ad77d Compare October 7, 2026 09:34
@renovate renovate Bot changed the title chore(deps): update dependency pymongo to v4.18.2 [security] Update dependency pymongo to v4.18.2 [SECURITY] Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

@renovate
renovate Bot force-pushed the renovate/pypi-pymongo-vulnerability branch from 73ad77d to c0c2a7a Compare October 8, 2026 13:24
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Overall Project 48.23% 🍏

There is no coverage information present for the Files changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants