{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pymongo-3.5.0---4.18.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mongodb:pymongo:*:*:*:*:*:python:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-96748"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PyMongo (3.5.0 - 4.18.1)"],"_cs_severities":["high"],"_cs_tags":["pymongo","injection","database","vulnerability"],"_cs_type":"advisory","_cs_vendors":["MongoDB"],"content_html":"\u003cp\u003ePyMongo versions 3.5.0 through 4.18.1 contain a host injection vulnerability (CVE-2026-96748) resulting from improper parsing of connection strings. The driver performs global percent-decoding on the host component of the connection string before splitting the string into individual \u003ccode\u003ehost:port\u003c/code\u003e targets. An attacker who can influence the input interpolated into a connection string (such as user-provided hostnames or identifiers) can inject a comma (\u003ccode\u003e%2C\u003c/code\u003e) or colon (\u003ccode\u003e%3A\u003c/code\u003e) into the input. These sequences are ignored by many URL-validation checks but are decoded into functional delimiters by PyMongo, allowing the attacker to inject an arbitrary server into the client's seed list. This exposes the application to topology discovery or authentication requests directed toward attacker-controlled infrastructure, potentially leaking credentials or allowing the redirection of database operations. The vulnerability was addressed in PyMongo 4.18.2 by deferring percent-decoding to apply only to specific Unix domain socket paths after host splitting has occurred.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an application endpoint that accepts user-controlled input (e.g., tenant ID, hostname, or API key).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious input string containing encoded delimiters, such as \u003ccode\u003elegit-db.example.com%2Cmalicious-host.com\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application blindly interpolates this string into a MongoDB connection URI.\u003c/li\u003e\n\u003cli\u003eThe PyMongo client receives the connection URI and passes the host section to the vulnerable parsing logic.\u003c/li\u003e\n\u003cli\u003eThe parser calls \u003ccode\u003eunquote_plus\u003c/code\u003e on the entire host segment, converting \u003ccode\u003e%2C\u003c/code\u003e to \u003ccode\u003e,\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe parser splits the resulting string into a list of hosts, now including the attacker-supplied \u003ccode\u003emalicious-host.com\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe PyMongo driver attempts to connect to or perform topology discovery against both the legitimate host and the attacker's host.\u003c/li\u003e\n\u003cli\u003eAttacker-controlled host receives authentication attempts or database operations, leading to credential harvesting or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to perform man-in-the-middle attacks, capture authentication credentials, and potentially reroute database operations. This vulnerability affects any application using PyMongo versions 3.5.0 through 4.18.1 that constructs connection strings using unsanitized or insufficiently validated user-provided data. While the scope of impact depends on the application's implementation, it represents a significant risk for multi-tenant applications or platforms that dynamically generate connection URIs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of PyMongo to version 4.18.2 or later immediately to patch CVE-2026-96748.\u003c/li\u003e\n\u003cli\u003eAudit application codebases for dynamic construction of MongoDB connection strings, specifically looking for string interpolation of user-supplied variables.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or allowlisting for any variables used in connection strings; prevent the injection of characters such as \u003ccode\u003e%\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, or \u003ccode\u003e/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eUse parameterized configuration management instead of constructing URIs at runtime where possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T06:43:05Z","date_published":"2026-10-06T06:43:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pymongo-host-injection/","summary":"A vulnerability in PyMongo (CVE-2026-96748) allows attackers to inject malicious host entries into connection strings via percent-encoded delimiters, potentially leading to unauthorized data routing or credential theft.","title":"PyMongo Host Injection via Percent-Encoded Delimiters","url":"https://feed.craftedsignal.io/briefs/2026-10-pymongo-host-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - PyMongo (3.5.0 - 4.18.1)","version":"https://jsonfeed.org/version/1.1"}