mediumVulnerability

CVE-2026-88029

### Impact When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match. ### Patches Patch available in pymongo >= 4.18.1 ### Workarounds Ensure your existing workflow _only_ supports exact matching on the GridFS API.

Properties

severity
medium
summary
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
epss_score
0.00476
retrieved_at
2026-10-06T03:06:48+00:00
ghsa_published
2026-10-05T23:27:13Z
source_url
https://github.com/advisories/GHSA-8fvv-fgr5-f8ch
ghsa_updated
2026-10-05T23:27:14Z
ghsa_id
GHSA-8fvv-fgr5-f8ch
last_source
FIRST EPSS
cve_id
CVE-2026-88029
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
false
epss_percentile
0.38935

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Special Elements in Data Query Logic

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pymongo

AFFECTS (1)

→[Software]pip/pymongo

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88029 — Ninja Signal Threat Intelligence | Ninja Signal