Hi,
The following vulnerabilities were published for pymongo.
CVE-2026-96747[0]:
| The client-side field level encryption support in the MongoDB Python
| Driver can treat a key management endpoint value ending in ".sock"
| as a local Unix domain socket path rather than a remote host. A user
| with write access to the encryption key metadata stored in the
| database can cause an application using the driver to open
| connections to local sockets on the application host. Data sent over
| these connections is limited to the start of a TLS handshake, so no
| chosen content is transmitted.
CVE-2026-96748[1]:
| PyMongo's connection string parsing decodes percent-encoded
| characters in the host portion before the host list is separated on
| its delimiters. When an application places a hostname value supplied
| by an unauthenticated party into a connection string, that party may
| cause additional servers of their choosing to be added to the
| application's database client. The application may then send its
| authentication exchange and database operations to one of those
| servers, which can observe limited information and return altered
| results.
CVE-2026-96749[2]:
| An integer overflow in the BSON document encoding component of the
| MongoDB Python Driver's bundled native extension may occur when a
| single document is built from an unusually large amount of caller-
| supplied data. Size arithmetic is performed in a signed 32-bit type,
| and the guard meant to catch the overflow is written in a form whose
| behavior is not defined by the C language standard. A party with no
| privileges who can place a very large value into data that an
| application encodes may, depending on how the native extension was
| built, cause a write outside the bounds of an allocated buffer
| inside the application's own process.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-96747
https://www.cve.org/CVERecord?id=CVE-2026-96747
[1] https://security-tracker.debian.org/tracker/CVE-2026-96748
https://www.cve.org/CVERecord?id=CVE-2026-96748
[2] https://security-tracker.debian.org/tracker/CVE-2026-96749
https://www.cve.org/CVERecord?id=CVE-2026-96749
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore