Skip to content

Prep 4.18.2 release - #3066

Merged
NoahStapp merged 5 commits into
mongodb:v4.18from
NoahStapp:v4.18
Sep 24, 2026
Merged

NoahStapp merged 5 commits into
mongodb:v4.18from
NoahStapp:v4.18

Conversation

@NoahStapp

Copy link
Copy Markdown
Contributor

PYTHON-XXXX

Changes in this PR

Test Plan

Checklist

Checklist for Author

  • Did you update the changelog (if necessary)?
  • Is there test coverage?
  • Is any followup work tracked in a JIRA ticket? If so, add link(s).

Checklist for Reviewer

  • Does the title of the PR reference a JIRA Ticket?
  • Do you fully understand the implementation? (Would you be comfortable explaining how this code works to someone else?)
  • Is all relevant documentation (README or docstring) updated?

aclark4life and others added 4 commits September 24, 2026 12:24
* SECBUG-4278 Don't decode percent-encoded delimiters in URI hosts

_validate_uri and _parse_srv both called unquote_plus on the whole
host section before splitting it into individual host:port entries.
A percent-encoded "," or ":" in an attacker-influenced hostname
fragment therefore decoded into a real delimiter, injecting an
extra, attacker-chosen host and port into the seed list on every
parse. Move the percent-decoding into split_hosts and apply it only
to Unix domain socket paths (identified by their unescaped ".sock"
suffix before decoding), the only host identifiers that legitimately
need it, and only after splitting on ",".

* PYTHON-5986 Reject percent-encoded hostnames, preserve IPv6 zone indexes

An IPv6 zone index is escaped as %25 (RFC 6874), so sockets are not the
only host identifier that legitimately requires decoding; decode those
too. Any other percent-encoding in a hostname is now rejected with
InvalidURI rather than passed through as an unresolvable host.

* PYTHON-5986 Address review feedback on test names and comments

* PYTHON-5986 Simplify test comments

* PYTHON-5986 Remove changelog entry
* SECBUG-4279 Reject Unix domain socket KMS endpoints

_EncryptionIO.kms_request passed the KMS endpoint from a data key's
masterKey.endpoint verbatim to parse_host(), which returns strings
ending in ".sock" unchanged, bypassing hostname/port validation.
_create_connection then treats any address ending in ".sock" as a
Unix domain socket path and connects to it with AF_UNIX. Since
masterKey.endpoint is read back from the key vault on every KMS
request, a party able to write a key vault document could redirect
the driver's KMS connection to an arbitrary local socket on the
application host. Reject ".sock"-suffixed KMS endpoints immediately
after parsing, before any connection is attempted.

* PYTHON-5990 Drop spec test number from non-spec test name

* PYTHON-5990 Drop duplicated comment from kms_request guard

* PYTHON-5990 Reference PYTHON ticket in test and neutralize changelog wording

* PYTHON-5990 Remove changelog entry
* PYTHON-5996 Harden bson buffer size guard against signed integer overflow

* PYTHON-5996 Add changelog entry

* remove changelog entry for now

* Update doc/changelog.rst

* Update doc/changelog.rst

* Update doc/changelog.rst

* Update doc/changelog.rst
@NoahStapp
NoahStapp requested a review from blink1073 September 24, 2026 16:37
@NoahStapp
NoahStapp requested a review from a team as a code owner September 24, 2026 16:37
blink1073
blink1073 previously approved these changes Sep 24, 2026

@blink1073 blink1073 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@NoahStapp
NoahStapp merged commit 640dd23 into mongodb:v4.18 Sep 24, 2026
31 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants