Skip to content

[Aikido] Fix security issue in pymongo via minor version upgrade from 4.16.0 to 4.18.2 - #4

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-SECURITY-213-update-packages-127755747-6quc
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-SECURITY-213-update-packages-127755747-6quc

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade PyMongo to fix host injection via percent-encoded delimiters and heap buffer overflow in BSON encoding.

✅ 2 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-814334
HIGH
[pymongo] A connection string parsing vulnerability allows injection of arbitrary hosts into the client's seed list when untrusted input is interpolated into the host portion, enabling topology discovery and authentication against attacker-controlled servers. The issue stems from premature percent decoding of delimiters before host splitting.
AIKIDO-2026-506971
HIGH
[pymongo] A heap out-of-bounds write vulnerability exists in the BSON encoder due to signed 32-bit integer overflow in buffer growth calculations, allowing remote code execution when encoding large documents with attacker-controlled data.
🔗 Related Tasks
🤖 Remediation details

Fix pymongo security vulnerabilities by updating minimum version to 4.18.2

Short summary

This PR remediates two high-severity vulnerabilities in pymongo by raising its declared minimum version in the root pyproject.toml and refreshing uv.lock. The pymongo package is a direct dependency of the project, so the fix required only a single manifest edit and a lockfile regeneration.

pymongo

pymongo was declared as >=4.16.0 in pyproject.toml, which allowed the resolver to pin version 4.16.0—a version within the affected ranges (≥2.2.1 and ≤4.18.1 / ≥1.10.1 and ≤4.18.1) for both advisories. The lower bound was raised to >=4.18.2 (the minimum patched release), causing uv lock to resolve the package to 4.18.2 and eliminating all vulnerable instances from uv.lock.

Version changes

Package From To Why updated
pymongo >=4.16.0 (resolved 4.16.0) >=4.18.2 (resolved 4.18.2) Direct CVE fix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants