Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-96748

PyMongo connection-string host injection

PyMongo can decode percent-encoded characters in a connection string before it splits the host list. An untrusted hostname can add a server. Fixed in 4.18.2. NVD scores it 8.3. This is not confirmed code execution.

CVSS
8.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Class
Other
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
MongoDB
Products
PyMongo
Affected
PyMongo before 4.18.2, when the application places an untrusted hostname into the connection string.
Fixed
4.18.2
Published
24 Sept 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-96748 is a connection-string parsing bug in PyMongo. NVD says percent-encoded characters in the host portion are decoded before the host list is split. If an application puts a hostname from an unauthenticated party into that string, extra servers can be added to the client. The application may then send its authentication exchange and operations to one of those servers. The published impact is limited observation and altered results, scored 8.3 on CVSS 4.0, with an attack requirement. CWE-177.

The 4.18.2 release notes list this CVE among the fixes in that version, along with CVE-2026-96747 and CVE-2026-96749. Those two are not this record. CISA has not listed CVE-2026-96748. NVD does not describe arbitrary code execution.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-96748