Bug 2540686 (CVE-2026-96747)

Summary: CVE-2026-96747 pymongo: pymongo: Forced local socket connection via manipulated key management endpoint
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in pymongo. When client-side field-level encryption is configured, the driver misinterprets Key Management Service (KMS) endpoint addresses ending in '.sock' as local Unix domain socket files rather than remote network hosts. An authenticated database user with permission to modify encryption key metadata can exploit this behavior to force the application into opening connections to local sockets on the host system. While data transmitted across these connections is limited to an initial Transport Layer Security (TLS) handshake, it may trigger unintended interactions with local services running on the application server.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2542958, 2542959    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-24 18:33:27 UTC
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.