Disclosure summary
### Summary PyMongo passed the KMS endpoint of a data key verbatim into `parse_host()`, which returns any string ending in `.sock` unchanged instead of validating it as a hostname and port. The driver's connection code then treats such an address as a Unix domain socket path and connects to it with `AF_UNIX`. Because the endpoint originates from `masterKey.endpoint` in a key vault document, a party who can write to the key vault could redirect the driver's KMS connection to an arbitrary Unix domain socket path on the application host. ### Impact An application using client-side field level encryption (CSFLE) or Queryable Encryption is affected if an attacker can write to its key vault collection. Setting `masterKey.endpoint` on a data key to a `.sock`-suffixed string causes the next KMS request for that key (key cache TTL is ~60 seconds) to open an `AF_UNIX` connection to the attacker-chosen filesystem path from inside the victim application process. The documented custom KMS endpoint feature supports TCP hosts only, so this crosses a boundary the feature was never intended to allow. Impact is limited to the side effects of the connection itself. The socket is still wrapped in a ve
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-qx36-8mw2-4r3x
Open original source · Updated Oct 05, 2026
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
Source severity: MEDIUM / 5.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | pymongo | >= 3.9.0, | 4.18.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-05T19:46:53-04:00
MODIFIED 2026-10-05T19:46:54-04:00
INGESTED 2026-10-06T11:45:42-04:00