Improper Handling of URL Encoding (Hex Encoding) Affecting pymongo package, versions [3.5.0,4.18.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PYMONGO-20158849
  • published27 Sept 2026
  • disclosed24 Sept 2026
  • creditUnknown

Introduced: 24 Sep 2026

NewCVE-2026-96748  (opens in a new tab)
CWE-177  (opens in a new tab)

How to fix?

Upgrade pymongo to version 4.18.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of URL Encoding (Hex Encoding) in _validate_uri and _parse_srv, which apply unquote_plus to the entire host section of a connection string before splitting it on , and :, so a percent-encoded delimiter decodes into a real one. An attacker can add a server they control to the client's seed list, which then receives topology discovery and authentication attempts carrying the application's credentials, by supplying a value containing %2C or %3A where the application interpolates untrusted input such as a tenant name or hostname fragment into the URI. This requires the application to build its connection string from request data, and Unix domain socket paths, the one host form that legitimately needs percent-encoding, are not affected.

CVSS Base Scores

version 4.0
version 3.1