PyMongo, Forced Unix Domain Socket Connection, CVE-2026-96747 (Medium) -DC-Oct2026-2748

Listen to this Post

to CVE-2026-96747

The MongoDB Python Driver (PyMongo) contains a path resolution flaw within its client-side field level encryption (CSFLE) implementation. The driver passes the KMS endpoint value stored in a data key’s `masterKey.endpoint` field verbatim to the internal `parse_host()` function. When this value ends with the suffix .sock, `parse_host()` returns the string unchanged, bypassing the hostname and port validation that applies to all other endpoint formats. The connection logic in `_create_connection()` and its asynchronous equivalent then checks whether the host string ends with `.sock` and, if so, treats it as a filesystem path for an `AF_UNIX` socket connection. This means a party who can write to the key vault collection can redirect the driver’s KMS request to an arbitrary Unix domain socket path on the application host. The key vault document’s `masterKey.endpoint` field originates from user‑writable metadata, so an attacker with write access to the key vault can inject a .sock‑suffixed value. The next KMS request for that key, which occurs within the key cache TTL of approximately 60 seconds, will attempt to connect to the attacker‑chosen socket path. The socket is still wrapped in a verifying TLS context using the `.sock` string as the server_hostname, and insecure KMS TLS options are rejected, so the TLS handshake always fails and the KMS payload is never transmitted. The attacker controls the connect target but not the bytes sent; only a fixed TLS ClientHello is emitted. Applications that do not use CSFLE or Queryable Encryption are not affected, and applications whose key vault is not writable by untrusted parties are likewise not affected. The vulnerability corresponds to CWE‑918 (Server‑Side Request Forgery) and has a CVSS v3.1 score of 5.0 (Medium). The flaw was fixed in PyMongo 4.18.2 by rejecting any .sock‑suffixed KMS endpoint with a `pymongo.errors.ConfigurationError` immediately after parsing.

DailyCVE Form:

Platform: PyMongo
Version: < 4.18.2
Vulnerability: Forced AF_UNIX connect
Severity: Medium
date: 2026-09-24

Prediction: 2026-09-24

What Undercode Say

Analytics

Bash command to check PyMongo version:

pip show pymongo | grep Version

Python code snippet showing the vulnerable parsing path:

from pymongo.encryption import _EncryptionIO
Vulnerable: endpoint passed verbatim to parse_host
endpoint = "malicious.sock"
_EncryptionIO.kms_request calls parse_host(endpoint, 443)
parse_host returns "malicious.sock" unchanged
then _create_connection sees host.endswith(".sock") and performs AF_UNIX connect

Command to audit key vault documents for `.sock` endpoints:

mongosh --eval 'db.getSiblingDB("keyvault").keys.find({"masterKey.endpoint": /.sock$/})'

Exploit: (Educational Purposes!)

An attacker with write access to the key vault collection updates a data key’s `masterKey.endpoint` field to a .sock‑suffixed string, such as /tmp/attacker.sock. Within the next key cache refresh (approximately 60 seconds), the victim application’s PyMongo driver reads the key vault document, passes the endpoint to parse_host(), and then attempts an `AF_UNIX` connection to the specified filesystem path. The connection is wrapped in a TLS context that uses the `.sock` string as server_hostname, causing the handshake to fail immediately. The attacker cannot send arbitrary data, but can force the application process to open a local socket connection to a path of their choosing.

Protection: from this CVE

Upgrade to PyMongo 4.18.2 or later, which rejects .sock‑suffixed KMS endpoints with `ConfigurationError` before any connection attempt. If immediate upgrade is not possible, restrict write access to the key vault collection to trusted principals only. Additionally, validate `masterKey.endpoint` on all data keys you create and audit existing key vault documents for any endpoints ending in .sock.

Impact:

The impact is limited to the side effects of the forced connection. The attacker controls the connect target but not the transmitted bytes, as the driver only sends a fixed TLS ClientHello before the handshake fails. This can lead to local socket enumeration, file descriptor exhaustion, or denial‑of‑service conditions against local services listening on the targeted Unix domain socket. No encryption key material or application payload is transmitted over the connection. Applications not using CSFLE or Queryable Encryption, or whose key vault is not writable by untrusted parties, are not affected.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top