CVE-2026-6691: MongoDB C Driver

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

Affected products

  • MongoDB C Driver: from 2.1.0, before 2.1.2 (fixed in 2.1.2)

Published 2026-05-06. Last modified 2026-06-18.