<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pymongo - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/pymongo/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 06:43:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/pymongo/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PyMongo Host Injection via Percent-Encoded Delimiters</title><link>https://feed.craftedsignal.io/briefs/2026-10-pymongo-host-injection/</link><pubDate>Tue, 06 Oct 2026 06:43:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pymongo-host-injection/</guid><description>A vulnerability in PyMongo (CVE-2026-96748) allows attackers to inject malicious host entries into connection strings via percent-encoded delimiters, potentially leading to unauthorized data routing or credential theft.</description><content:encoded><![CDATA[<p>PyMongo versions 3.5.0 through 4.18.1 contain a host injection vulnerability (CVE-2026-96748) resulting from improper parsing of connection strings. The driver performs global percent-decoding on the host component of the connection string before splitting the string into individual <code>host:port</code> targets. An attacker who can influence the input interpolated into a connection string (such as user-provided hostnames or identifiers) can inject a comma (<code>%2C</code>) or colon (<code>%3A</code>) into the input. These sequences are ignored by many URL-validation checks but are decoded into functional delimiters by PyMongo, allowing the attacker to inject an arbitrary server into the client's seed list. This exposes the application to topology discovery or authentication requests directed toward attacker-controlled infrastructure, potentially leaking credentials or allowing the redirection of database operations. The vulnerability was addressed in PyMongo 4.18.2 by deferring percent-decoding to apply only to specific Unix domain socket paths after host splitting has occurred.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an application endpoint that accepts user-controlled input (e.g., tenant ID, hostname, or API key).</li>
<li>Attacker crafts a malicious input string containing encoded delimiters, such as <code>legit-db.example.com%2Cmalicious-host.com</code>.</li>
<li>The application blindly interpolates this string into a MongoDB connection URI.</li>
<li>The PyMongo client receives the connection URI and passes the host section to the vulnerable parsing logic.</li>
<li>The parser calls <code>unquote_plus</code> on the entire host segment, converting <code>%2C</code> to <code>,</code>.</li>
<li>The parser splits the resulting string into a list of hosts, now including the attacker-supplied <code>malicious-host.com</code>.</li>
<li>The PyMongo driver attempts to connect to or perform topology discovery against both the legitimate host and the attacker's host.</li>
<li>Attacker-controlled host receives authentication attempts or database operations, leading to credential harvesting or data exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to perform man-in-the-middle attacks, capture authentication credentials, and potentially reroute database operations. This vulnerability affects any application using PyMongo versions 3.5.0 through 4.18.1 that constructs connection strings using unsanitized or insufficiently validated user-provided data. While the scope of impact depends on the application's implementation, it represents a significant risk for multi-tenant applications or platforms that dynamically generate connection URIs.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of PyMongo to version 4.18.2 or later immediately to patch CVE-2026-96748.</li>
<li>Audit application codebases for dynamic construction of MongoDB connection strings, specifically looking for string interpolation of user-supplied variables.</li>
<li>Implement strict input validation or allowlisting for any variables used in connection strings; prevent the injection of characters such as <code>%</code>, <code>:</code>, <code>,</code>, or <code>/</code>.</li>
<li>Use parameterized configuration management instead of constructing URIs at runtime where possible.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>pymongo</category><category>injection</category><category>database</category><category>vulnerability</category></item></channel></rss>