pymongo is vulnerable to Server-Side Request Forgery (SSRF)
53
Medium Risk
PyMongo passes a data key's masterKey.endpoint straight into parse_host(), which returns any string ending in .sock unchanged instead of checking it as a host and port. The connection code then uses that value as a Unix domain socket path and connects to it with AF_UNIX, so a party who can write to the key vault collection can redirect the driver's KMS connection to an arbitrary Unix domain socket on the application host. Impact is limited because the socket is still wrapped in a verifying TLS context with the .sock string as server_hostname, so the handshake fails and no KMS message is sent. The fix makes _EncryptionIO.kms_request reject a KMS endpoint ending in .sock with a configuration error right after parsing, on both the synchronous and asynchronous paths.
You are affected if you are using a version that falls within the vulnerable range and you use client side field level encryption or Queryable Encryption with a key vault collection that untrusted parties can write to.
pymongo is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.10.0 - 4.18.1.
Upgrade the pymongo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.