CVE-2026-96749
- EPSS 0.13%
- Veröffentlicht 24.09.2026 18:18:13
- Zuletzt bearbeitet 26.09.2026 04:17:52
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a si...
CVE-2026-96748
- EPSS 0.26%
- Veröffentlicht 24.09.2026 18:18:12
- Zuletzt bearbeitet 24.09.2026 21:00:46
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string,...
CVE-2026-96747
- EPSS 0.13%
- Veröffentlicht 24.09.2026 18:18:10
- Zuletzt bearbeitet 24.09.2026 21:04:40
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metad...
CVE-2026-88029
- EPSS 0.26%
- Veröffentlicht 10.09.2026 17:56:25
- Zuletzt bearbeitet 29.09.2026 16:06:45
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An...