PyMongo CSPI via Host Decoding
CVE-2026-96748 Published on September 24, 2026

Connection redirection via percent-encoded delimiter injection in connection string hosts
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.

NVD

Vulnerability Analysis

CVE-2026-96748 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

What is a Hex Encoding Vulnerability?

The software does not properly handle when all or part of an input has been URL encoded.

CVE-2026-96748 has been classified to as a Hex Encoding vulnerability or weakness.


Affected Versions

MongoDB Python Driver: