Server-side Request Forgery (SSRF) Affecting pymongo package, versions [3.9.0,4.18.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PYMONGO-20158824
  • published27 Sept 2026
  • disclosed24 Sept 2026
  • creditUnknown

Introduced: 24 Sep 2026

NewCVE-2026-96747  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade pymongo to version 4.18.2 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in _EncryptionIO.kms_request and _EncryptionIO.fetch_keys, which pass the endpoint through parse_host() and on to _create_connection unchanged when it ends in .sock, so the connection code interprets it as a Unix domain socket path and connects over AF_UNIX rather than to a network host. A user with write access to the key vault collection can make the application open a connection to a filesystem path of their choosing from inside its own process, by setting masterKey.endpoint on a data key to a value with that suffix. This requires the application to use client side field level encryption or Queryable Encryption against a key vault the attacker can write to, and TLS verification on the KMS connection causes the attempt to fail, which confines the effect to the connection itself.

Note: This is only exploitable if an attacker has write access to the key vault collection used by the application.

Workaround

This vulnerability can be avoided by restricting key vault write access to trusted principals and auditing existing key vault documents for .sock suffixed endpoint values.

CVSS Base Scores

version 4.0
version 3.1