AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-88029.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.1CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

### Impact When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match. ### Patches Patch available in pymongo >= 4.18.1 ### Workarounds Ensure your existing workflow _only_ supports exact matching on the GridFS API.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-8fvv-fgr5-f8ch

Open original source · Updated Oct 05, 2026

pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods

Source severity: MEDIUM / 6.1

EcosystemPackageAffected rangeFirst patched
pippymongo4.18.1

Original records & references

PUBLISHED 2026-10-05T19:27:13-04:00
MODIFIED 2026-10-05T19:27:14-04:00
INGESTED 2026-10-06T11:45:33-04:00