Executive brief
A security vulnerability exists in the MongoDB C Driver, a software component used by applications to communicate with MongoDB databases. An attacker could exploit this flaw by providing a specially crafted connection string, potentially leading to a system crash or unauthorized code execution. This issue occurs during the initial connection phase, even before the user has successfully logged in.
Technical details
A heap-based buffer overflow vulnerability (CWE-120/CWE-787) exists in the MongoDB C Driver's Cyrus SASL integration. The flaw is rooted in unsafe string copying during the username canonicalization process. An attacker can trigger this overflow by passing a long, untrusted username string within a MongoDB URI when the 'authMechanism' is set to 'GSSAPI'. This occurs locally before authentication or network traffic is initiated. Successful exploitation could lead to arbitrary code execution or a denial-of-service (DoS) condition. The issue is fixed in versions 2.1.3 and 2.2.0.
Affected products
- MongoDB MongoDB C Driver 2.1.0 to 2.1.2
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2025-10-24: patched: Issue resolved in development tracking.