Bug 2540686 (CVE-2026-96747)
| Summary: | CVE-2026-96747 pymongo: pymongo: Forced local socket connection via manipulated key management endpoint | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in pymongo. When client-side field-level encryption is configured, the driver misinterprets Key Management Service (KMS) endpoint addresses ending in '.sock' as local Unix domain socket files rather than remote network hosts. An authenticated database user with permission to modify encryption key metadata can exploit this behavior to force the application into opening connections to local sockets on the host system. While data transmitted across these connections is limited to an initial Transport Layer Security (TLS) handshake, it may trigger unintended interactions with local services running on the application server.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2542958, 2542959 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-24 18:33:27 UTC
|