PyMongo Host Injection via Percent-Encoded Delimiters
A vulnerability in PyMongo (CVE-2026-96748) allows attackers to inject malicious host entries into connection strings via percent-encoded delimiters, potentially leading to unauthorized data routing or credential theft.
CVE search metadata
CVE search record: CVE-2026-96748. Severity: medium. CVSS: 6.5. EPSS: 0.26%. KEV: no. Product: PyMongo (3.5.0 - 4.18.1). Brief: PyMongo Host Injection via Percent-Encoded Delimiters. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pymongo-host-injection/
PyMongo versions 3.5.0 through 4.18.1 contain a host injection vulnerability (CVE-2026-96748) resulting from improper parsing of connection strings. The driver performs global percent-decoding on the host component of the connection string before splitting the string into individual host:port targets. An attacker who can influence the input interpolated into a connection string (such as user-provided hostnames or identifiers) can inject a comma (%2C) or colon (%3A) into the input. These sequences are ignored by many URL-validation checks but are decoded into functional delimiters by PyMongo, allowing the attacker to inject an arbitrary server into the client's seed list. This exposes the application to topology discovery or authentication requests directed toward attacker-controlled infrastructure, potentially leaking credentials or allowing the redirection of database operations. The vulnerability was addressed in PyMongo 4.18.2 by deferring percent-decoding to apply only to specific Unix domain socket paths after host splitting has occurred.
Attack Chain
- Attacker identifies an application endpoint that accepts user-controlled input (e.g., tenant ID, hostname, or API key).
- Attacker crafts a malicious input string containing encoded delimiters, such as
legit-db.example.com%2Cmalicious-host.com. - The application blindly interpolates this string into a MongoDB connection URI.
- The PyMongo client receives the connection URI and passes the host section to the vulnerable parsing logic.
- The parser calls
unquote_pluson the entire host segment, converting%2Cto,. - The parser splits the resulting string into a list of hosts, now including the attacker-supplied
malicious-host.com. - The PyMongo driver attempts to connect to or perform topology discovery against both the legitimate host and the attacker's host.
- Attacker-controlled host receives authentication attempts or database operations, leading to credential harvesting or data exfiltration.
Impact
Successful exploitation allows attackers to perform man-in-the-middle attacks, capture authentication credentials, and potentially reroute database operations. This vulnerability affects any application using PyMongo versions 3.5.0 through 4.18.1 that constructs connection strings using unsanitized or insufficiently validated user-provided data. While the scope of impact depends on the application's implementation, it represents a significant risk for multi-tenant applications or platforms that dynamically generate connection URIs.
Recommendation
- Upgrade all instances of PyMongo to version 4.18.2 or later immediately to patch CVE-2026-96748.
- Audit application codebases for dynamic construction of MongoDB connection strings, specifically looking for string interpolation of user-supplied variables.
- Implement strict input validation or allowlisting for any variables used in connection strings; prevent the injection of characters such as
%,:,,, or/. - Use parameterized configuration management instead of constructing URIs at runtime where possible.
Immediate actions
Upgrade PyMongo to 4.18.2 or later across all production environments
Mitigations
Remove or sanitize user input used in connection string construction
CVE-2026-96748