Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-587q-94wg-2pfp

Опубликовано: 06 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.8

Описание

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

EPSS

Процентиль: 3%
0.00126
Низкий

8.6 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-120
CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

CVSS3: 7.8
nvd
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

CVSS3: 7.8
debian
3 месяца назад

The MongoDB C Driver's Cyrus SASL integration performs unsafe string c ...

CVSS3: 8.4
redos
7 дней назад

Уязвимость mongo-c-driver

EPSS

Процентиль: 3%
0.00126
Низкий

8.6 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-120
CWE-787