Vulnerabilities
Vulnerable Software
Mongodb:  >> C Driver  >> 2.1.0  Security Vulnerabilities
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.
CVSS Score
8.6
EPSS Score
0.001
Published
2026-05-06
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVSS Score
6.9
EPSS Score
0.002
Published
2025-11-18


Contact Us

Shodan ® - All rights reserved