PT-2026-98231 · Mongodb · Mongo-Python-Driver
CVE-2026-96747
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MongoDB Python Driver (affected versions not specified)
Description
Client-side field level encryption support may incorrectly interpret a key management endpoint value ending in ".sock" as a local Unix domain socket path instead of a remote host. An attacker with write access to the encryption key metadata in the database can force the application to establish connections to local sockets on the host machine. The data transmitted during these connections is restricted to the beginning of a TLS handshake, preventing the transmission of arbitrary content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongo-Python-Driver