Debian Package Tracker
Register | Log in
Subscribe

pymongo

Choose email to subscribe with

general
  • source: pymongo (main)
  • version: 4.18.1-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Aryan Karamtoth [DMD] [DM]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.11.0-1
  • o-o-sec: 3.11.0-1+deb11u1
  • oldstable: 3.11.0-1+deb12u1
  • stable: 4.10.1-6
  • testing: 4.18.1-1
  • unstable: 4.18.1-1
versioned links
  • 3.11.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.11.0-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.11.0-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.10.1-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.18.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-pymongo-doc
  • python3-bson
  • python3-bson-ext
  • python3-gridfs
  • python3-pymongo
  • python3-pymongo-ext
action needed
Marked for autoremoval on 03 November due to python-anyio: #1148561 high
Version 4.18.1-1 of pymongo is marked for autoremoval from testing on Tue 03 Nov 2026. It depends (transitively) on python-anyio, affected by #1148561. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-22 Last update: 2026-10-01 17:31
A new upstream version is available: 4.18.2 high
A new upstream version 4.18.2 is available, you should consider packaging it.
Created: 2026-09-28 Last update: 2026-10-01 13:02
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-96747: The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.
  • CVE-2026-96748: PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
  • CVE-2026-96749: An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
Created: 2026-09-25 Last update: 2026-09-28 17:30
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-96747: The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.
  • CVE-2026-96748: PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
  • CVE-2026-96749: An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
Created: 2026-09-25 Last update: 2026-09-28 17:30
4 security issues in bookworm high

There are 4 open security issues in bookworm.

3 important issues:
  • CVE-2026-96747: The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.
  • CVE-2026-96748: PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
  • CVE-2026-96749: An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.
1 issue postponed or untriaged:
  • CVE-2026-88029: (postponed; to be fixed through a stable update) Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.
Created: 2026-09-25 Last update: 2026-09-28 17:30
4 low-priority security issues in trixie low

There are 4 open security issues in trixie.

4 issues left for the package maintainer to handle:
  • CVE-2026-88029: (needs triaging) Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.
  • CVE-2026-96747: (needs triaging) The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver to open connections to local sockets on the application host. Data sent over these connections is limited to the start of a TLS handshake, so no chosen content is transmitted.
  • CVE-2026-96748: (needs triaging) PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be added to the application's database client. The application may then send its authentication exchange and database operations to one of those servers, which can observe limited information and return altered results.
  • CVE-2026-96749: (needs triaging) An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is written in a form whose behavior is not defined by the C language standard. A party with no privileges who can place a very large value into data that an application encodes may, depending on how the native extension was built, cause a write outside the bounds of an allocated buffer inside the application's own process.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-11 Last update: 2026-09-28 17:30
news
[rss feed]
  • [2026-09-18] pymongo 4.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-15] Accepted pymongo 4.18.1-1 (source) into unstable (Aryan Karamtoth)
  • [2026-06-22] pymongo 4.17.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-18] Accepted pymongo 4.17.0-1 (source) into unstable (Santiago Vila)
  • [2026-01-31] pymongo 4.16.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-14] Accepted pymongo 4.16.0-1 (source) into unstable (Aryan Karamtoth) (signed by: Colin Watson)
  • [2025-12-10] pymongo 4.15.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-06] Accepted pymongo 4.15.5-1 (source) into unstable (Aryan Karamtoth) (signed by: Colin Watson)
  • [2025-11-30] pymongo 4.15.4-2 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted pymongo 4.15.4-2 (source) into unstable (Aryan Karamtoth)
  • [2025-11-27] pymongo 4.15.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-24] Accepted pymongo 4.15.4-1 (source) into unstable (Colin Watson)
  • [2025-10-28] pymongo 4.15.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-24] Accepted pymongo 4.15.3-2 (source) into unstable (Colin Watson)
  • [2025-10-16] pymongo 4.15.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-11] Accepted pymongo 4.15.3-1 (source) into unstable (Alexandre Detiste)
  • [2025-05-04] pymongo 4.10.1-6 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted pymongo 4.10.1-6 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2025-02-10] pymongo 4.10.1-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-31] Accepted pymongo 4.10.1-5 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2025-01-03] Removed 4.7.3-2 from experimental (Debian FTP Masters)
  • [2024-12-23] pymongo 4.10.1-4 MIGRATED to testing (Debian testing watch)
  • [2024-12-10] Accepted pymongo 4.10.1-4 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2024-12-02] pymongo 4.10.1-3 MIGRATED to testing (Debian testing watch)
  • [2024-11-21] Accepted pymongo 4.10.1-3 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2024-10-19] pymongo 4.10.1-2 MIGRATED to testing (Debian testing watch)
  • [2024-10-14] Accepted pymongo 4.10.1-2 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2024-10-11] Accepted pymongo 4.10.1-1 (source) into unstable (Salvo 'LtWorf' Tomaselli)
  • [2024-09-16] Accepted pymongo 3.11.0-1+deb11u1 (source) into oldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2024-06-21] pymongo 4.7.3-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.17.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing