Bug 2531586 (CVE-2026-88029)
| Summary: | CVE-2026-88029 pymongo: MongoDB Python Driver: Data disclosure and denial of service via query-operator injection | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anthomas, eglynn, ehelms, ggainey, jjoyce, jpasqual, jpretori, jschluet, juwatts, lhh, mburns, mdellweg, mgarciac, mhulan, nmoumoul, osousa, pcreech, rchan, rhel-process-autobot, smallamp, tmalecek, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the GridFS component of the MongoDB Python Driver (pymongo). The driver can treat a caller-supplied structured file identifier as a MongoDB query condition instead of a literal identifier. An authenticated user who can influence the identifier passed to GridFS download, delete, or rename operations may retrieve stored file content beyond the intended target, delete all GridFS chunks in the affected bucket (rendering stored files unreadable), or rename a file other than the intended target.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2535878, 2535879, 2535847, 2535849 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-10 18:12:33 UTC
|