MongoDB / Python Driver
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96749 | Heap out-of-bounds write via signed size overflow in BSON document encoding | HIGH | 7.5 | Sep 24, 2026 |
| CVE-2026-96748 | Connection redirection via percent-encoded delimiter injection in connection string hosts | HIGH | 8.3 | Sep 24, 2026 |
| CVE-2026-96747 | Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encryption | MEDIUM | 5.3 | Sep 24, 2026 |
| CVE-2026-88029 | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python Driver | MEDIUM | 6.1 | Sep 10, 2026 |
Showing 1 to 4 of 4 CVEs