Intel

AIKIDO-2026-149161

pymongo is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-96747 Published Yesterday

53

Medium Risk

This Affects:

PYTHONpymongo
3.10.0 - 4.18.1
Fixed in 4.18.2
Are you affected? Scan for Free

TL;DR

PyMongo passes a data key's masterKey.endpoint straight into parse_host(), which returns any string ending in .sock unchanged instead of checking it as a host and port. The connection code then uses that value as a Unix domain socket path and connects to it with AF_UNIX, so a party who can write to the key vault collection can redirect the driver's KMS connection to an arbitrary Unix domain socket on the application host. Impact is limited because the socket is still wrapped in a verifying TLS context with the .sock string as server_hostname, so the handshake fails and no KMS message is sent. The fix makes _EncryptionIO.kms_request reject a KMS endpoint ending in .sock with a configuration error right after parsing, on both the synchronous and asynchronous paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use client side field level encryption or Queryable Encryption with a key vault collection that untrusted parties can write to.

Background info

pymongo is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.10.0 - 4.18.1.

How to fix this

Upgrade the pymongo library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform