Intel

AIKIDO-2026-814334

pymongo is vulnerable to Improper Handling of URL Encoding (Hex Encoding)

Improper Handling of URL Encoding (Hex Encoding)CVE-2026-96748 Published Yesterday

83

High Risk

This Affects:

PYTHONpymongo
2.2.1 - 4.18.1
Fixed in 4.18.2
Are you affected? Scan for Free

TL;DR

PyMongo decodes percent encoding across the entire host section of a connection string before splitting it into individual host:port entries. A percent encoded , or : inside a single hostname decodes into a real delimiter and injects an extra host and port into the client's seed list. When an application interpolates untrusted input into the host portion of a URI, a value that looks like one hostname to the application becomes two hosts to the driver, and the client can run topology discovery and authentication against the injected host. The fix moves decoding into split_hosts so the string is split on , first, and only Unix domain socket paths and IPv6 zone indexes are percent decoded afterward.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application interpolates untrusted input into the host portion of a MongoDB connection string.

Background info

pymongo is vulnerable to Improper Handling of URL Encoding (Hex Encoding) in versions 2.2.1 - 4.18.1.

How to fix this

Upgrade the pymongo library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform