mongodb/node-mongodb-native · error · MongoAPIError

Server record does not share hostname with parent URI

Error message

Server record does not share hostname with parent URI

What it means

Thrown by checkParentDomainMatch() when a resolved SRV record address's domain does not end with the srvHost's domain. The driver enforces that every SRV-advertised host be a subdomain of the srvHost from the connection string; a mismatch implies DNS hijacking or misconfiguration. Raised as MongoAPIError.

Solutions

  1. Correct the DNS SRV records so all targets are subdomains of the srvHost in the connection string.
  2. Verify with 'dig SRV _mongodb._tcp.<srvHost>' that every returned target ends with the srvHost domain.
  3. If unintended, investigate possible DNS tampering or a stale/cached record.
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await client.connect();
} catch (e) {
  if (e instanceof MongoAPIError && /does not share hostname/.test(e.message)) {
    // investigate DNS: SRV records must be subdomains of the srvHost
  } else throw e;
}

Prevention

When it happens

Trigger: Connecting via mongodb+srv:// where a DNS SRV response returns a hostname that is not under the srvHost domain (e.g. srvHost is cluster.example.com but an SRV record points to evil.attacker.com). This is the core SRV hostname-verification guard.

Common situations: Compromised or misconfigured DNS server returning out-of-domain addresses. Using a custom SRV hostname whose records were edited to point at an unrelated host. Internal DNS changes that forget to update SRV targets.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/31d50b6106be0643. Report an issue: GitHub.

Appendix: source

Thrown at src/utils.ts:1186

  //   will not satisfy an addressDomain that endsWith '.fake-trusted.site'
  const addressDomain = `.${normalizedAddress.replace(allCharacterBeforeFirstDot, '')}`;
  let srvHostDomain = srvIsLessThanThreeParts
    ? normalizedSrvHost
    : `.${normalizedSrvHost.replace(allCharacterBeforeFirstDot, '')}`;

  if (!srvHostDomain.startsWith('.')) {
    srvHostDomain = '.' + srvHostDomain;
  }
  if (
    srvIsLessThanThreeParts &&
    normalizedAddress.split('.').length <= normalizedSrvHost.split('.').length
  ) {
    throw new MongoAPIError(
      'Server record does not have at least one more domain level than parent URI'
    );
  }
  if (!addressDomain.endsWith(srvHostDomain)) {
    throw new MongoAPIError('Server record does not share hostname with parent URI');
  }
}

/**
 * Perform a get request that returns status and body.
 * @internal
 */
export function get(
  url: URL | string,
  options: http.RequestOptions = {}
): Promise<{ body: string; status: number | undefined }> {
  return new Promise((resolve, reject) => {
    /* eslint-disable prefer-const */
    let timeoutId: NodeJS.Timeout;
    const request = http
      .get(url, options, response => {
        response.setEncoding('utf8');
        let body = '';

View on GitHub (pinned to dce7939f86)