CVE-2026-96747

Public on 2026-09-24
Modified on 2026-09-25
Description
A flaw was found in pymongo. When client-side field-level encryption is configured, the driver misinterprets Key Management Service (KMS) endpoint addresses ending in '.sock' as local Unix domain socket files rather than remote network hosts. An authenticated database user with permission to modify encryption key metadata can exploit this behavior to force the application into opening connections to local sockets on the host system. While data transmitted across these connections is limited to an initial Transport Layer Security (TLS) handshake, it may trigger unintended interactions with local services running on the application server.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 python-pymongo Pending Fix
Amazon Linux 2027 Preview python-pymongo Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N