GHSA-vp6j-j7w5-5xjj: Medium severity pip/pymongo vulnerability

Published Oct 5, 2026
·
Updated

Summary

PyMongo percent-decoded the entire host section of a connection string before splitting it into individual host:port entries. A percent-encoded , or : in a hostname therefore decoded into a real delimiter, injecting an additional attacker-chosen host and port into the client's seed list.

Impact

An application that interpolates untrusted input into a MongoDB connection string -- for example, a tenant name or hostname fragment taken from a request -- could be made to add an attacker-controlled server to the seed list. Because %2C and %3A survive most URL-safety checks and only become delimiters inside PyMongo's parser, input that looks like a single hostname to the application becomes two hosts to the driver. The client may then perform topology discovery and authentication against the attacker's host, exposing credentials, or route operations to it.

Unix domain socket paths, the only host identifiers that legitimately require percent-encoding, are not affected.

Patches

Fixed in PyMongo 4.18.2. Percent-decoding was moved into splithosts and now applies only to Unix domain socket paths, identified by an unescaped .sock suffix before decoding, and only after splitting on ,.

Workarounds

Do not interpolate untrusted input into the host portion of a connection string. If unavoidable, reject or percent-decode-and-validate the value before building the URI.

Details

The decoding was introduced in PyMongo 3.5.0 (PYTHON-1282), where unquoteplus was applied to the whole host section in validateuri and, later, parsesrv, before the string was split on , and :.

Affected Software

1 affected componentFixes available
pip/pymongo>=3.5.0<=4.18.1
4.18.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pymongo to a version that resolves this vulnerability.

    Fixed in 4.18.2
  2. Upgrade

    Upgrade PyMongo to a version that resolves this vulnerability.

    Fixed in 4.18.2
  3. Compensating control

    Do not interpolate untrusted input into the host portion of a MongoDB connection string; if unavoidable, reject the value or percent-decode and validate it before building the URI.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:47 PM
Data Sourced
via GitHub·11:47 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are realistically exposed?

Applications using PyMongo are exposed when they interpolate untrusted input into a MongoDB connection string's host section, such as a tenant name or hostname fragment supplied in a request. Applications that construct host entries only from trusted, validated values are not described as affected by this attack path.

2

What does an attacker need to provide to exploit this issue?

The attacker needs influence over data inserted into the connection string host section and must be able to include a percent-encoded comma or colon, such as %2C or %3A. These values can appear URL-safe to the application but are decoded by the vulnerable parser into host delimiters.

3

What is the potential impact of a successful injection?

An attacker can add an attacker-controlled host and port to the client's seed list. The client may perform topology discovery and authentication against that host, potentially exposing credentials or routing operations to it.

4

How can I determine whether my application is at risk?

Review code that builds MongoDB connection strings for untrusted values placed in the host list, especially values that may contain percent-encoded commas or colons. Unix domain socket paths are not affected by this issue.

5

What should I do to remediate the issue?

Update PyMongo to version 4.18.2, which changes percent-decoding so it applies only to Unix domain socket paths. Until updating, do not interpolate untrusted input into the connection-string host section and reject or otherwise prevent encoded delimiter values from reaching it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203