CVE-2026-96748
CVE-2026-96748 is a medium-severity vulnerability with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-177.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 8.3
- EPSS exploit prediction: 0% (16th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-177
- Published:
- Last modified:
Description
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
Frequently asked questions
- What is CVE-2026-96748?
- PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
- How severe is CVE-2026-96748?
- CVE-2026-96748 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity high, and availability none.
- Is CVE-2026-96748 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (16th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-96748?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-96748 published?
- CVE-2026-96748 was published on 2026-09-24.
References
- https://github.com/mongodb/mongo-python-driver/blob/4.18.2/doc/changelog.rst
- https://github.com/mongodb/mongo-python-driver/releases/tag/4.18.2
- https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj
Other CWE-177 vulnerabilities
- CVE-2026-76504 — Critical (CVSS 9.8): A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
- CVE-2026-59083 — Critical (CVSS 9.1): Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security…
- CVE-2026-41041 — Critical (CVSS 9.1): URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects…
- CVE-2026-22037 — High (CVSS 8.4): The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in…
- CVE-2026-22031 — High (CVSS 8.4): @fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in…
- CVE-2026-15371 — High (CVSS 8.1): Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and…