CVE-2026-96748
PyMongo connection-string host injection
PyMongo can decode percent-encoded characters in a connection string before it splits the host list. An untrusted hostname can add a server. Fixed in 4.18.2. NVD scores it 8.3. This is not confirmed code execution.
- CVSS
- 8.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
- Class
- Other
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- MongoDB
- Products
- PyMongo
- Affected
- PyMongo before 4.18.2, when the application places an untrusted hostname into the connection string.
- Fixed
- 4.18.2
- CWE
- CWE-177
- Published
- 24 Sept 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-96748 is a connection-string parsing bug in PyMongo. NVD says percent-encoded characters in the host portion are decoded before the host list is split. If an application puts a hostname from an unauthenticated party into that string, extra servers can be added to the client. The application may then send its authentication exchange and operations to one of those servers. The published impact is limited observation and altered results, scored 8.3 on CVSS 4.0, with an attack requirement. CWE-177.
The 4.18.2 release notes list this CVE among the fixes in that version, along with CVE-2026-96747 and CVE-2026-96749. Those two are not this record. CISA has not listed CVE-2026-96748. NVD does not describe arbitrary code execution.