SUSE-SU-2026:4398-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264398-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4398-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4398-1
Upstream
CVE (3)
Related
Published
2026-09-29T16:18:54Z
Modified
2026-09-30T12:00:04Z
Summary
Security update for python-pymongo
Details

This update for python-pymongo fixes the following issues:

  • CVE-2026-96747: improper handling of key management endpoint values ending in .sock allows users with write access to the encryption key metadata to open connections to local sockets on the application host (bsc#1282844).
  • CVE-2026-96748: host injection in connection string leading to database connection redirection due to improper connection string parsing (bsc#1282827).
  • CVE-2026-96749: integer overflow in BSON document encoding allows an unprivileged user to write outside the bounds of an allocated buffer (bsc#1282845).
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7 / python-pymongo

Package

Name
python-pymongo
Purl
pkg:rpm/suse/python-pymongo&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "python3-pymongo":  "3.11.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4398-1.json"