CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-96748

CVE-2026-96748: Host Injection Vulnerability in PyMongo Connection String Parsing

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 6, 2026·7 min read·1 visit

Executive Summary (TL;DR)

PyMongo's parser decoded percent-encoded characters before splitting hostnames, allowing attackers to inject rogue servers into connection strings.

A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.

Vulnerability Overview

CVE-2026-96748 is a host injection vulnerability affecting the official MongoDB Python driver, PyMongo. The issue is located in the connection string parsing routine, specifically within the host extraction and resolution pipeline. This vulnerability occurs when applications dynamically construct MongoDB connection URIs utilizing untrusted hostnames supplied by unauthenticated third parties.

The vulnerability allows an attacker to inject arbitrary backend servers into the database client's connection pool. By crafting hostnames containing percent-encoded delimiters, such as a comma (%2C) or a colon (%3A), attackers can manipulate the connection state. The driver parses these values incorrectly, causing the client to establish connections to external, unauthorized servers.

This bug class is classified under CWE-177: Improper Handling of URL Encoding. The impact of the flaw is significant, potentially leading to unauthorized data exposure or malicious manipulation of database operations. The vulnerability was officially resolved in PyMongo version 4.18.2, which was released on September 24, 2026.

Root Cause Analysis

The vulnerability originates from the sequence of decoding and parsing tasks in the PyMongo URI parser modules. In affected versions of PyMongo, the driver extracts the entire host list from the connection URI as a single string. It then processes this raw string before dividing it into separate node addresses.

Specifically, the parser executes a global percent-decoding operation on the entire host block using Python's unquote_plus() function. After decoding the entire string, PyMongo invokes functions to split the string on delimiters like commas and colons. This structural ordering allows percent-encoded commas (%2C) and colons (%3A) to be decoded into actual comma and colon characters before the split occurs.

Because the decoding happens before the string splitting, characters intended as payload data are promoted to structural delimiters. The parser subsequently treats the newly decoded commas and colons as boundaries for separate host addresses. This design flaw permits any percent-encoded string to generate arbitrary entries in the driver's internal server list.

Code Analysis: Vulnerable vs. Patched Code

Prior to the patch, the connection string parsing logic in pymongo/synchronous/uri_parser.py (and its asynchronous counterpart) decoded the entire host segment prematurely. The variable containing the raw host addresses was passed to unquote_plus() in a single step. This resulted in the global expansion of all escaped characters across the entire substring.

# Vulnerable implementation in pymongo/synchronous/uri_parser.py
# The entire hosts string is unquoted before any delimiter checks occur
hosts = unquote_plus(hosts)
 
# The decoded string is subsequently split on the comma character
for entity in hosts.split(","):
    # This processes each entry, which now includes injected elements
    nodes.append(parse_host(entity, default_port))

The fix implemented in version 4.18.2 restructures the processing order to guarantee that splitting occurs before decoding. The global unquote_plus() call was removed entirely from the main parsing loop. The utility function split_hosts in pymongo/uri_parser_shared.py now enforces strict structural separation before performing any decoding logic.

# Patched implementation in pymongo/uri_parser_shared.py
def split_hosts(hosts: str, default_port: Optional[int] = DEFAULT_PORT) -> list[tuple[str, Optional[int]]]:
    nodes = []
    # Splitting occurs directly on the raw, undecoded hosts string
    for entity in hosts.split(","):
        if not entity:
            raise ConfigurationError("Empty host (or extra comma in host list)")
        port = default_port
        node = entity
        
        # Percent-decoding is now restricted to specific valid use cases
        if entity.endswith(".sock"):
            node = unquote_plus(entity)
            port = None
        elif entity.startswith("["):
            node = entity.replace("%25", "%")
        elif "%" in entity:
            # Rejects percent-encoding in standard hostnames
            raise InvalidURI(
                "Percent-encoding is only allowed in Unix domain socket paths "
                f"and IPv6 zone indexes, not in hostnames: {entity}"
            )
        nodes.append(parse_host(node, port))
    return nodes

This structural change ensures that standard TCP hostnames cannot contain percent-encoded control characters. Any attempt to supply a hostname containing a percent character will trigger an InvalidURI exception. The patch also updates KMS endpoint validation to prevent similar exploitation vectors when managing client-side field-level encryption.

Exploitation Methodology & Proof of Concept

Exploitation of this vulnerability requires an application configuration where untrusted input is interpolated into the host field of a MongoDB connection string. An attacker must find an interface that dynamically populates host values, such as a database-as-a-service manager or a tenant routing system. By supplying a crafted string, the attacker initiates the exploit chain.

For example, if an attacker registers with a hostname value of legit-host.internal%2Cattacker-dns.com%3A27017, the application inserts this string into the connection URI. During parsing, PyMongo extracts the host portion as a single entity and decodes the %2C to a comma and %3A to a colon. The driver then splits the string, yielding two distinct connection destinations: legit-host.internal and attacker-dns.com:27017.

Once parsed, both destinations are registered in the MongoClient's internal connection pool or replica set seed list. The client subsequently initiates background discovery and connection tasks to both addresses. This behavior allows the attacker's server to participate in the application's database communication channels without requiring any prior authentication.

Impact Assessment

The impact of successful host injection is critical for confidentiality and integrity. By forcing the PyMongo client to connect to an attacker-controlled server, the attacker can intercept network packets containing authentication requests. Although PyMongo employs secure authentication mechanisms like SCRAM-SHA-256, the server receives connection handshakes containing user identifiers and challenge hashes.

Beyond credential exposure, the injected server can act as an adversary-in-the-middle. If the application configuration permits query routing to secondary members of a replica set, the client may send queries directly to the rogue server. The attacker's server can return modified or fabricated data payloads to the client application, leading to integrity violations.

This vulnerability does not directly lead to arbitrary code execution on the client server. However, the capacity to manipulate query responses and harvest connection information poses a substantial threat to application security. The National Vulnerability Database assigned this flaw a CVSS v3.1 score of 6.5, while the MongoDB CNA assigned a CVSS v4.0 score of 8.3, reflecting the severe consequences in multi-tenant environments.

Remediation & Secure Coding Practices

The recommended remediation is to upgrade the PyMongo package to version 4.18.2 or later. This version contains the structural patch that restricts percent-decoding to Unix domain socket paths and IPv6 zone indexes. Upgrading the package resolves the vulnerability at the parser level without requiring modifications to connection logic.

If an immediate package upgrade is not feasible, developers must implement strict input validation on all user-supplied host parameters. Hostnames should be verified against a strict regular expression that allows only alphanumeric characters, periods, and hyphens. Any input containing percent characters, commas, or colons must be rejected before connection string interpolation occurs.

import re
 
def sanitize_and_validate_host(host_input: str) -> str:
    # Restrict input to standard domain name characters
    if not re.match(r"^[a-zA-Z0-9.-]+$", host_input):
        raise ValueError("Invalid characters detected in host input")
    return host_input

Enforcing network-level egress restrictions is also a viable defense-in-depth measure. Configuring firewall rules to limit outgoing database connections to known, authorized IP ranges prevents the PyMongo client from establishing contact with external, rogue database seeds.

Official Patches

MongoDBPYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
MongoDBOfficial PyMongo 4.18.2 Release Tag

Fix Analysis (2)

Technical Appendix

CVSS Score
8.3/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Probability
0.26%
Top 84% most exploited

Affected Systems

PyMongo (Python Driver for MongoDB)

Affected Versions Detail

Product
Affected Versions
Fixed Version
PyMongo
MongoDB
>= 0, < 4.18.24.18.2
AttributeDetail
CWE IDCWE-177
Attack VectorNetwork
CVSS v4.0 Score8.3
EPSS Score0.00257 (15.78th percentile)
ImpactHost Injection / Adversary-in-the-Middle
Exploit StatusNone (No public PoC)
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1557Adversary-in-the-Middle
Credential Access
T1090Proxy
Command and Control
CWE-177
Improper Handling of URL Encoding (Hex Encoding)

The application does not properly decode percent-encoded characters before validating or parsing structural delimiters, leading to delimiter injection.

References & Sources

  • [1]GitHub Security Advisory GHSA-vp6j-j7w5-5xjj
  • [2]Fix Commit: Refactoring of host split and decode order
  • [3]CVE Record for CVE-2026-96748
  • [4]Official PyMongo Changelog

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-96749
8.4

CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.

Alon Barad
Alon Barad
4 views•6 min read
•about 2 hours ago•CVE-2026-102827
8.1

CVE-2026-102827: Command and Argument Injection Bypass in simple-git via Option Abbreviation

CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.

Alon Barad
Alon Barad
6 views•7 min read
•about 3 hours ago•CVE-2026-102826
8.1

CVE-2026-102826: Argument Validation Bypass and Command Injection in simple-git

CVE-2026-102826 is a critical security vulnerability discovered in the simple-git library for Node.js, affecting all versions prior to v4.0.0. The vulnerability allows remote attackers to bypass the library's built-in argument validation rules using conditional configuration includes and abbreviated Command Line Interface (CLI) options. By injecting custom arguments into Git execution pipelines, an attacker can force the application to load a malicious local configuration file, resulting in arbitrary OS command execution under the privileges of the parent Node.js process.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-102828
9.2

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

Amit Schendel
Amit Schendel
9 views•5 min read
•about 5 hours ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
6 views•5 min read
•about 6 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
9 views•7 min read