PyMongo 的连接字符串解析在按分隔符拆分主机列表之前,会先对主机部分进行 URL 百分号编码解码。当应用程序将未经验证用户提供的 hostname 值嵌入连接字符串时,攻击者可以利用此机制向应用的数据库客户端注入额外的、由攻击者指定名称的服务器。此后,应用程序可能将其身份验证交换过程和数据库操作发送至这些被注入的服务器,导致攻击者能够观察有限的通信信息,并返回篡改后的响应结果。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | Python Driver | 0 ~ 4.18.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96749 | 8.4 HIGH | Heap out-of-bounds write via signed size overflow in BSON document encoding |
| CVE-2026-96750 | 7.1 HIGH | Shell script injection via server-supplied database name in Open MongoDB shell |
| CVE-2026-96744 | 7.1 HIGH | Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB |
| CVE-2026-96746 | 6.5 MEDIUM | Heap buffer overflow via mid-scan command list growth in client topology monitoring |
| CVE-2026-96745 | 5.6 MEDIUM | PHP object injection via unsuppressible __pclass class inference in command monitoring eve |
| CVE-2026-96747 | 5.0 MEDIUM | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt |
No comments yet