mediumCVSS 5Vulnerability

CVE-2026-96747

### Summary PyMongo passed the KMS endpoint of a data key verbatim into `parse_host()`, which returns any string ending in `.sock` unchanged instead of validating it as a hostname and port. The driver's connection code then treats such an address as a Unix domain socket path and connects to it with `AF_UNIX`. Because the endpoint originates from `masterKey.endpoint` in a key vault document, a party who can write to the key vault could redirect the driver's KMS connection to an arbitrary Unix domain socket path on the application host. ### Impact An application using client-side field level encryption (CSFLE) or Queryable Encryption is affected if an attacker can write to its key vault collection. Setting `masterKey.endpoint` on a data key to a `.sock`-suffixed string causes the next KMS request for that key (key cache TTL is ~60 seconds) to open an `AF_UNIX` connection to the attacker-chosen filesystem path from inside the victim application process. The documented custom KMS endpoint feature supports TCP hosts only, so this crosses a boundary the feature was never intended to allow. Impact is limited to the side effects of the connection itself. The socket is still wrapped in a verifying TLS context using the `.sock` string as `server_hostname`, and insecure KMS TLS options are rejected, so the handshake always fails and the KMS message is never sent. The attacker controls the connect target but not the transmitted bytes (a fixed TLS ClientHello). Applications that do not use CSFLE or Queryable Encryption are not affected. Applications whose key vault is not writable by untrusted parties are not affected. ### Patches Fixed in PyMongo 4.18.2 `_EncryptionIO.kms_request` now rejects a `.sock`-suffixed KMS endpoint with `pymongo.errors.ConfigurationError` immediately after parsing, before any connection is attempted, on both the synchronous and asynchronous paths. No application code changes are required beyond upgrading. ### Workarounds If you cannot upgrade

Properties

severity
medium
summary
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
epss_score
0.00131
cvss_score
5
retrieved_at
2026-10-06T03:06:48+00:00
ghsa_published
2026-10-05T23:46:53Z
source_url
https://github.com/advisories/GHSA-qx36-8mw2-4r3x
ghsa_updated
2026-10-05T23:46:54Z
ghsa_id
GHSA-qx36-8mw2-4r3x
last_source
FIRST EPSS
cve_id
CVE-2026-96747
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
false
epss_percentile
0.02262

Related Entities (6)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]pip/pymongo

AFFECTS (1)

→[Software]pip/pymongo

HAS_WEAKNESS (2)

→[Weakness]Server-Side Request Forgery (SSRF)
→[Weakness]Improper Input Validation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-96747 (CVSS 5) — Ninja Signal Threat Intelligence | Ninja Signal