Junglewise Threat Intelligence

CVE-2026-6691: MongoDB C Driver heap buffer overflow in Cyrus SASL integration

CVE-2026-6691 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: MongoDB C Driver. Vendors: MongoDB.

Executive brief

A security vulnerability exists in the MongoDB C Driver, a software component used by applications to communicate with MongoDB databases. An attacker could exploit this flaw by providing a specially crafted connection string, potentially leading to a system crash or unauthorized code execution. This issue occurs during the initial connection phase, even before the user has successfully logged in.

Technical details

A heap-based buffer overflow vulnerability (CWE-120/CWE-787) exists in the MongoDB C Driver's Cyrus SASL integration. The flaw is rooted in unsafe string copying during the username canonicalization process. An attacker can trigger this overflow by passing a long, untrusted username string within a MongoDB URI when the 'authMechanism' is set to 'GSSAPI'. This occurs locally before authentication or network traffic is initiated. Successful exploitation could lead to arbitrary code execution or a denial-of-service (DoS) condition. The issue is fixed in versions 2.1.3 and 2.2.0.

Affected products

  • MongoDB MongoDB C Driver 2.1.0 to 2.1.2

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2025-10-24: patched: Issue resolved in development tracking.

References

Related threats