Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96748— Connection redirection via percent-encoded delimiter injection in connection string hosts

Quick assessment

Affected
MongoDB Python Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PyMongo 的连接字符串解析在按分隔符拆分主机列表之前,会先对主机部分进行 URL 百分号编码解码。当应用程序将未经验证用户提供的 hostname 值嵌入连接字符串时,攻击者可以利用此机制向应用的数据库客户端注入额外的、由攻击者指定名称的服务器。此后,应用程序可能将其身份验证交换过程和数据库操作发送至这些被注入的服务器,导致攻击者能够观察有限的通信信息,并返回篡改后的响应结果。

CVSS 6.5 · Medium EPSS 0.26% · P16
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96748

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Connection redirection via percent-encoded delimiter injection in connection string hosts
Source: CVE Program / CVE List V5
Vulnerability Description
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
URL编码处理不恰当(Hex编码)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MongoDB Python Driver 0 ~ 4.18.2 -

II. Public POCs for CVE-2026-96748

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96748

请登录查看更多情报信息。

Other References for CVE-2026-96748 (3)

Same Patch Batch · MongoDB · 2026-09-24 · 7 CVEs total

CVE-2026-96749 8.4 HIGH Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-96750 7.1 HIGH Shell script injection via server-supplied database name in Open MongoDB shell
CVE-2026-96744 7.1 HIGH Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB
CVE-2026-96746 6.5 MEDIUM Heap buffer overflow via mid-scan command list growth in client topology monitoring
CVE-2026-96745 5.6 MEDIUM PHP object injection via unsuppressible __pclass class inference in command monitoring eve
CVE-2026-96747 5.0 MEDIUM Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encrypt

IV. Related Vulnerabilities

V. Comments for CVE-2026-96748

No comments yet


Leave a comment