CVE-2026-96747
Public on 2026-09-24
Modified on 2026-09-25
Description
A flaw was found in pymongo. When client-side field-level encryption is configured, the driver misinterprets Key Management Service (KMS) endpoint addresses ending in '.sock' as local Unix domain socket files rather than remote network hosts. An authenticated database user with permission to modify encryption key metadata can exploit this behavior to force the application into opening connections to local sockets on the host system. While data transmitted across these connections is limited to an initial Transport Layer Security (TLS) handshake, it may trigger unintended interactions with local services running on the application server.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | python-pymongo | Pending Fix | ||
| Amazon Linux 2027 Preview | python-pymongo | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |