CVE-2026-6691: MongoDB C Driver
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.
Affected products
- MongoDB C Driver: from 2.1.0, before 2.1.2 (fixed in 2.1.2)
Published 2026-05-06. Last modified 2026-06-18.