The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/CDRIVER-6134 | Patch Vendor Advisory Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-05-06 16:16
Updated : 2026-06-18 17:18
NVD link : CVE-2026-6691
Mitre link : CVE-2026-6691
CVE.ORG link : CVE-2026-6691
JSON object : View
Products Affected
mongodb
- c_driver
