UBUNTU-CVE-2026-96747

Source
https://ubuntu.com/security/CVE-2026-96747
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-96747
Upstream
Published
2026-09-24T19:17:00Z
Modified
2026-10-01T00:29:40Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.

References

Affected packages

Ubuntu:14.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6-1
2.6.2-1
2.6.3-1
2.6.3-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-bson",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python-bson-ext",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python-gridfs",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python-pymongo",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python-pymongo-ext",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python3-bson",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "2.6.3-1build1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "2.6.3-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:20.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.7.1-1.1
3.7.1-1.1build1
3.10.1-0ubuntu2
3.10.1-0ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-bson",
            "binary_version": "3.10.1-0ubuntu2.1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "3.10.1-0ubuntu2.1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "3.10.1-0ubuntu2.1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "3.10.1-0ubuntu2.1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "3.10.1-0ubuntu2.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:22.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.11.0-1build2
3.11.0-1build3
3.11.0-1build4
3.11.0-1ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-bson",
            "binary_version": "3.11.0-1ubuntu0.22.04.1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "3.11.0-1ubuntu0.22.04.1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "3.11.0-1ubuntu0.22.04.1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "3.11.0-1ubuntu0.22.04.1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "3.11.0-1ubuntu0.22.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:24.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.11.0-1build6
3.11.0-1build7
3.11.0-1build8
3.11.0-1ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-bson",
            "binary_version": "3.11.0-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "3.11.0-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "3.11.0-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "3.11.0-1ubuntu0.24.04.1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "3.11.0-1ubuntu0.24.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:26.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.10.1-6
4.15.3-1
4.15.3-2
4.15.5-1
4.16.0-1
4.16.0-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-bson",
            "binary_version": "4.16.0-1build1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "4.16.0-1build1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "4.16.0-1build1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "4.16.0-1build1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "4.16.0-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:Pro:16.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=esm-infra%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.3-1
3.2-1
3.2-1build1
3.2-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-bson",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-bson-ext",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-gridfs",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-pymongo",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-pymongo-ext",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-bson",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "3.2-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"
Ubuntu:Pro:18.04:LTS
pymongo

Package

Name
pymongo
Purl
pkg:deb/ubuntu/pymongo?arch=source&distro=esm-infra%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.0-1build2
3.6.1+dfsg1-1
3.6.1+dfsg1-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-bson",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-bson-ext",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-gridfs",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-pymongo",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python-pymongo-ext",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-bson",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-bson-ext",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-gridfs",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-pymongo",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        },
        {
            "binary_name": "python3-pymongo-ext",
            "binary_version": "3.6.1+dfsg1-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96747.json"