GHSA-vp6j-j7w5-5xjj: Medium severity pip/pymongo vulnerability
Summary
PyMongo percent-decoded the entire host section of a connection string before splitting it into individual host:port entries. A percent-encoded , or : in a hostname therefore decoded into a real delimiter, injecting an additional attacker-chosen host and port into the client's seed list.
Impact
An application that interpolates untrusted input into a MongoDB connection string -- for example, a tenant name or hostname fragment taken from a request -- could be made to add an attacker-controlled server to the seed list. Because %2C and %3A survive most URL-safety checks and only become delimiters inside PyMongo's parser, input that looks like a single hostname to the application becomes two hosts to the driver. The client may then perform topology discovery and authentication against the attacker's host, exposing credentials, or route operations to it.
Unix domain socket paths, the only host identifiers that legitimately require percent-encoding, are not affected.
Patches
Fixed in PyMongo 4.18.2. Percent-decoding was moved into splithosts and now applies only to Unix domain socket paths, identified by an unescaped .sock suffix before decoding, and only after splitting on ,.
Workarounds
Do not interpolate untrusted input into the host portion of a connection string. If unavoidable, reject or percent-decode-and-validate the value before building the URI.
Details
The decoding was introduced in PyMongo 3.5.0 (PYTHON-1282), where unquoteplus was applied to the whole host section in validateuri and, later, parsesrv, before the string was split on , and :.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pymongoto a version that resolves this vulnerability.Fixed in 4.18.2 - Upgrade
Upgrade
PyMongoto a version that resolves this vulnerability.Fixed in 4.18.2 - Compensating control
Do not interpolate untrusted input into the host portion of a MongoDB connection string; if unavoidable, reject the value or percent-decode and validate it before building the URI.
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications using PyMongo are exposed when they interpolate untrusted input into a MongoDB connection string's host section, such as a tenant name or hostname fragment supplied in a request. Applications that construct host entries only from trusted, validated values are not described as affected by this attack path.
What does an attacker need to provide to exploit this issue?
The attacker needs influence over data inserted into the connection string host section and must be able to include a percent-encoded comma or colon, such as %2C or %3A. These values can appear URL-safe to the application but are decoded by the vulnerable parser into host delimiters.
What is the potential impact of a successful injection?
An attacker can add an attacker-controlled host and port to the client's seed list. The client may perform topology discovery and authentication against that host, potentially exposing credentials or routing operations to it.
How can I determine whether my application is at risk?
Review code that builds MongoDB connection strings for untrusted values placed in the host list, especially values that may contain percent-encoded commas or colons. Unix domain socket paths are not affected by this issue.
What should I do to remediate the issue?
Update PyMongo to version 4.18.2, which changes percent-decoding so it applies only to Unix domain socket paths. Until updating, do not interpolate untrusted input into the connection-string host section and reject or otherwise prevent encoded delimiter values from reaching it.