CVE-2026-96748 | MongoDB PyMongo up to 4.18.1 Connection String Hostname input validation

SecurityVulns

A vulnerability, which was classified as critical, has been found in MongoDB PyMongo up to 4.18.1. Affected by this vulnerability is an unknown functionality of the component Connection String. The manipulation of the argument Hostname leads to improper input validation.

This vulnerability is traded as CVE-2026-96748. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More