DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-96747: CVE-2026-96747: Local Unix Domain Socket SSRF via KMS Endpoint Manipulation in PyMongo

CVE-2026-96747: Local Unix Domain Socket SSRF via KMS Endpoint Manipulation in PyMongo

Vulnerability ID: CVE-2026-96747
CVSS Score: 5.0
Published: 2026-10-05

A vulnerability in the Client-Side Field-Level Encryption (CSFLE) component of the MongoDB Python Driver (PyMongo) allows an attacker with database write access to trigger local Unix domain socket connections. By manipulating the Key Management Service (KMS) endpoint configuration inside the key vault collection to end with a '.sock' extension, an attacker forces the application to perform a Server-Side Request Forgery (SSRF) against internal Unix domain sockets.

TL;DR

PyMongo's CSFLE key management parsing evaluates '.sock' suffixes as local Unix domain sockets rather than remote hostnames. Attackers with database write access can exploit this to achieve local SSRF against Unix domain sockets on the application host.


Technical Details

  • CWE ID: CWE-918 (Server-Side Request Forgery)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 5.0 (Medium)
  • Exploit Maturity: none (no public PoC available)
  • CISA KEV Status: Not Listed
  • Privileges Required: Low (requires write access to key vault)
  • Impact Category: Low Confidentiality / Information Disclosure via SSRF

Affected Systems

  • Applications utilizing MongoDB Python Driver (PyMongo) client-side field-level encryption (CSFLE)
  • Applications running PyMongo in environments with exposed or sensitive local Unix domain sockets
  • PyMongo (MongoDB Python Driver): >= 3.9.0, < 4.18.2 (Fixed in: 4.18.2)

Code Analysis

Commit: 44119d0

Reject Unix domain socket KMS endpoints in both synchronous and asynchronous encryption clients.

Mitigation Strategies

  • Upgrade the MongoDB Python Driver (PyMongo) to version 4.18.2 or newer to enforce strict validation on KMS endpoints.
  • Restrict database-level privileges to prevent unauthorized users from performing write operations on CSFLE key vault collections.
  • Avoid mounting local Unix domain sockets (e.g., docker.sock) into containerized application environments.
  • Enable database auditing to monitor write, update, and insert activities within encryption-related metadata collections.

Remediation Steps:

  1. Identify all deployment environments running affected PyMongo versions (>=3.9.0, <4.18.2).
  2. Upgrade the PyMongo library using the package manager: pip install --upgrade pymongo>=4.18.2.
  3. Implement role-based access control (RBAC) in MongoDB to restrict 'insert' and 'update' permissions on the 'admin.datakeys' collection.
  4. Deploy system-level controls (e.g., AppArmor, SELinux) to block Python runtimes from interacting with unauthorized local IPC paths.

References


Read the full report for CVE-2026-96747 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)