CVE-2026-96748
HighAdvisory
Published 24 Sept 2026In the index since 26 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.3
- base score, highest
- EPSS
- 0.003
- 16th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 56
- of 18,035 indexed, latest versions
- Container images
- 67
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
Carried by container images the latest versions of 56 of 18,035 indexed charts deploy, on 67 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pymongodeb | 3.11.0-1+deb12u1 | no fix listed | 1 |
| pymongopypi | 3.6.1, 3.8.0, 3.9.0, 3.10.0+20 more | 4.18.2 | 67 |
- OSV records
- DEBIAN-CVE-2026-96748GHSA-vp6j-j7w5-5xjj
Charts affected
56 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| qubivaqubiva | 0.3.2 | 1 of 3See more | 7,891 |
| checkmkrtomik-helm-chartsVerified publisher | 0.1.0 | 1 of 1See more | 9,245 |
| first-chartshashkist-test | 0.1.0 | 1 of 3See more | 3,642 |
| servicexssl-hep | 1.8.6 | 1 of 16See more | 61,371 |
| flask-contactstest-configmap | 1.0.1 | 1 of 3See more | 6,337 |
| xkopsxkops | 0.1.0 | 2 of 5See more | 15,307 |
Container images carrying it
67 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.