Your message dated Tue, 15 Sep 2026 00:34:03 +0000
with message-id <[email protected]>
and subject line Bug#1147408: fixed in pymongo 4.18.1-1
has caused the Debian Bug report #1147408,
regarding pymongo: CVE-2026-88029
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1147408: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147408
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pymongo
Version: 4.17.0-1
Severity: important
Tags: security upstream
Forwarded: https://jira.mongodb.org/browse/PYTHON-5994
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for pymongo.

CVE-2026-88029[0]:
| Improper neutralization of special elements in data query logic in
| the GridFS component of the MongoDB Python Driver can cause a
| caller-supplied structured file identifier to be interpreted as a
| query condition rather than as a literal identifier. An
| authenticated user who can influence the identifier passed by an
| affected application may obtain stored file content beyond the
| intended target or cause all GridFS file chunks in the affected
| bucket to be removed, rendering stored file content unreadable. The
| affected rename operation may also rename a stored file other than
| the intended target.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88029
    https://www.cve.org/CVERecord?id=CVE-2026-88029
[1] https://jira.mongodb.org/browse/PYTHON-5994
[2] 
https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: pymongo
Source-Version: 4.18.1-1
Done: Aryan Karamtoth <[email protected]>

We believe that the bug you reported is fixed in the latest version of
pymongo, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aryan Karamtoth <[email protected]> (supplier of updated pymongo 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 05:21:39 +0530
Source: pymongo
Architecture: source
Version: 4.18.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Aryan Karamtoth <[email protected]>
Closes: 1147408
Changes:
 pymongo (4.18.1-1) unstable; urgency=medium
 .
   * New upstream version 4.18.1
   * Introduce upstream fix for CVE-2026-88029 (Closes: #1147408)
   * Remove replace event loop policy patch, no longer needed
Checksums-Sha1:
 b005d83ed554ddfa3662be44988f6cadaf040de1 2565 pymongo_4.18.1-1.dsc
 a5159b9b333d47b88864f2caf2e430bd6ce85434 2823774 pymongo_4.18.1.orig.tar.gz
 fb3f0beff333558469d701f1586a8a33bff383d8 7484 pymongo_4.18.1-1.debian.tar.xz
 7ce421d61bbb9cb69f4701e87cb60b8b5464a213 10051 pymongo_4.18.1-1_amd64.buildinfo
Checksums-Sha256:
 23a630c9a2250db1963176a65c044ea558036d048fc098c7ee1ad1cc8f511d85 2565 
pymongo_4.18.1-1.dsc
 31f8a96de1aba291b1cdeceec35dcaf293c98d261a83117f5b11207bbb046438 2823774 
pymongo_4.18.1.orig.tar.gz
 3022761c4f4e451d4f7f5f2f6dddc3e8f5755df60ab736276536f7c0dfec2edb 7484 
pymongo_4.18.1-1.debian.tar.xz
 6c9f6c703bded60e1ab27e521fe0dce2473bc8378e71164783a7ff3db9d57e4c 10051 
pymongo_4.18.1-1_amd64.buildinfo
Files:
 41f99cac7275dcb2875a77f49e2d2468 2565 python optional pymongo_4.18.1-1.dsc
 d915e32bb21d591a796c633340f72eb8 2823774 python optional 
pymongo_4.18.1.orig.tar.gz
 e1d593d73708c6354c5ecca1ecc2f008 7484 python optional 
pymongo_4.18.1-1.debian.tar.xz
 e244de3421bdfab1fa31ee3ea5d0ce1b 10051 python optional 
pymongo_4.18.1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEen2TCCvRm6+oO340/pAHuO1kBCEFAmqoj8MACgkQ/pAHuO1k
BCFb1w//crnjRduTqo8/EF7ohTMqiJ/jpjVEnyTTxRodkvFidutEqwqORnDjA4o8
+Me1hFPZV3XFFo+ekuPV02mHUqyw9j/Y2ZUI5Vb2uATnknKXfM5e4J9a5NhYcOl8
7+EqL4dsniSZ8x0EWSfbZvrdRf6O2Q+F3qtiby/MqnCn8fmZjkanLBxv8SzDWdAh
3gRVeQybaQx9DKZPdmi+NUH0i6/odbkC0gRPYh0ZB6TdDWFr/TWv0Pf7lk6aal1t
j4bwbhauWxoKGQBGfQJLuyFPudpiBB/q/2QPgywmtNV5AfSSnX3na9Fi1b+UOdzW
r5m82v+idSr2eJVKJiY6iGDz4VWIU+vZfYAIEEu8lqm5dPChFUnOfiNvrIlJCIy3
GegNfQUS+xKnHJmvSfJjBG9Ds5cT9akcJxD97Kfu6LWpcu7pdLhVnSRKuVy7PSLp
CKIJFkR0bY0eEizwsWzZDByhXJN+A50L0d6AjUGpSK9aFFeo7/Rs/Nv6kGH9kMIA
B6Cln1ivqAhr6DpVx2JudYpYIvpn3tKcdu7VPE2waiYcjRZ31K5v199SBmadCfGP
O0cna3rLOewdkrfUHscYz67k5OxETXy4bKz//vzm0E2wMrASRNQUpTTLJ7I5o0MF
YE/R+k/eYrz+rIqbvsFAFZBx+G6obPGdIgndjd9n8kiS0s/HMCI=
=/3h9
-----END PGP SIGNATURE-----

Attachment: pgpdap5VKo4iB.pgp
Description: PGP signature


--- End Message ---

Reply via email to