Vulnerability GHSA-8fvv-fgr5-f8ch
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 05, 2026 at 11:27 PM UTC
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
0.1pre - 4.18.0
0.1pre - 4.18.0
Summary
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
Details
Impact
When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match.
Patches
Patch available in pymongo >= 4.18.1
Workarounds
Ensure your existing workflow only supports exact matching on the GridFS API.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
7 hours ago
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
0.1pre - 4.18.1 GHSA-v4x9-3549-crwv
0.1pre - 4.18.1 GHSA-v4x9-3549-crwv
Medium Risk
7 hours ago
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
3.5.0 - 4.18.1 GHSA-vp6j-j7w5-5xjj
3.5.0 - 4.18.1 GHSA-vp6j-j7w5-5xjj
Medium Risk
7 hours ago
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
3.9.0 - 4.18.1 GHSA-qx36-8mw2-4r3x
3.9.0 - 4.18.1 GHSA-qx36-8mw2-4r3x
Medium Risk
3 months ago
PyMongo Out-of-bounds Read in the bson module
0.1pre - 4.6.2 PYSEC-2026-1826
0.1pre - 4.6.2 PYSEC-2026-1826
Medium Risk
2 years ago
PyMongo Out-of-bounds Read in the bson module
0.1pre - 4.6.2 GHSA-m87m-mmvp-v9qm
0.1pre - 4.6.2 GHSA-m87m-mmvp-v9qm
Impacted packages
Timeline
Published
7 hours ago
October 05, 2026 at 11:27 PM UTC
Fixed (4.18.1)
25 days ago
September 10, 2026 at 02:55 PM UTC
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC