Vulnerability GHSA-8fvv-fgr5-f8ch

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 05, 2026 at 11:27 PM UTC
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
0.1pre - 4.18.0
0.1pre - 4.18.0

Summary

pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods

Details

Impact

When reading/writing via an ID with the GridFS API, require an exact match on the given ID. Otherwise, if a Hash is given in place of the ID, it may be interpreted as criteria, overriding the ID match.

Patches

Patch available in pymongo >= 4.18.1

Workarounds

Ensure your existing workflow only supports exact matching on the GridFS API.

Impacted packages

Timeline

Published
7 hours ago
October 05, 2026 at 11:27 PM UTC
Fixed (4.18.1)
25 days ago
September 10, 2026 at 02:55 PM UTC
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC