Bug 2540685 (CVE-2026-96748) - CVE-2026-96748 pymongo: pymongo: Database connection redirection via percent-encoded host delimiter injection
Summary: CVE-2026-96748 pymongo: pymongo: Database connection redirection via percent-...
Keywords:
Status: NEW
Alias: CVE-2026-96748
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2542960 2542961
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 18:33 UTC by OSIDB Bzimport
Modified: 2026-09-29 06:16 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 18:33:10 UTC
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.


Note You need to log in before you can comment on or make changes to this bug.