pymongo is vulnerable to Improper Handling of URL Encoding (Hex Encoding)
83
High Risk
PyMongo decodes percent encoding across the entire host section of a connection string before splitting it into individual host:port entries. A percent encoded , or : inside a single hostname decodes into a real delimiter and injects an extra host and port into the client's seed list. When an application interpolates untrusted input into the host portion of a URI, a value that looks like one hostname to the application becomes two hosts to the driver, and the client can run topology discovery and authentication against the injected host. The fix moves decoding into split_hosts so the string is split on , first, and only Unix domain socket paths and IPv6 zone indexes are percent decoded afterward.
You are affected if you are using a version that falls within the vulnerable range and your application interpolates untrusted input into the host portion of a MongoDB connection string.
pymongo is vulnerable to Improper Handling of URL Encoding (Hex Encoding) in versions 2.2.1 - 4.18.1.
Upgrade the pymongo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.