Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6691

Опубликовано: 06 мая 2026
Источник: debian
EPSS Низкий

Описание

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongo-c-driverfixed2.2.0-1package
mongo-c-driverfixed1.30.4-1+deb13u2trixiepackage
mongo-c-driverfixed1.23.1-1+deb12u3bookwormpackage
mongo-c-driverpostponedbullseyepackage

Примечания

  • https://jira.mongodb.org/browse/CDRIVER-6134

  • https://github.com/mongodb/mongo-c-driver/commit/b4984965877d559862e225beba09cb4e9d4a56a6 (2.2.0)

  • https://github.com/mongodb/mongo-c-driver/commit/d9c26f49e75d3de746a690db9c81ff5b4f6e21b0 (2.2.0)

EPSS

Процентиль: 3%
0.00126
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

CVSS3: 7.8
nvd
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

CVSS3: 7.8
github
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

EPSS

Процентиль: 3%
0.00126
Низкий