CVE-2026-96748

Public on 2026-09-24
Modified on 2026-09-25
Description
A flaw was found in pymongo. The driver improperly decodes percent-encoded characters in connection strings before separating host entries on delimiters. If an application incorporates untrusted hostnames into its connection strings, a remote attacker can inject arbitrary servers into the database client configuration. As a result, the application may connect to an attacker-controlled server, leading to data tampering and information disclosure.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 python-pymongo Pending Fix
Amazon Linux 2027 Preview python-pymongo Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N