openSUSE-SU-2026:22003-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22003-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:22003-1
Upstream
CVE (3)
Related
Published
2026-09-29T16:36:21Z
Modified
2026-10-01T18:23:24Z
Summary
Security update for python-pymongo
Details

This update for python-pymongo fixes the following issues:

Changes in python-pymongo:

  • CVE-2026-96749: integer overflow in BSON document encoding allows an unprivileged user to write outside the bounds of an allocated buffer (bsc#1282845)
  • CVE-2026-96748: host injection in connection string leading to database connection redirection due to improper connection string parsing (bsc#1282827)
  • CVE-2026-96747: improper handling of key management endpoint values ending in .sock allows users with write access to the encryption key metadata to open connections to local sockets on the application host (bsc#1282844)
References

Affected packages

openSUSE:Leap 16.0 / python-pymongo

Package

Name
python-pymongo
Purl
pkg:rpm/opensuse/python-pymongo&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.6.3-bp160.2.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-pymongo": "4.6.3-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22003-1.json"