216.73.217.22

CVE-2026-2303

· Published 10/02/2026 20:17 · Modified 10/02/2026 21:51

Labels: CVE-2026-2303 2026-02-10CVE-2026-2303CWE-183[email protected]

Essential information

Published
10/02/2026 20:17
Modified
10/02/2026 21:51
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mongodb / mongo go driver cpe:2.3:a:mongodb:mongo_go_driver:*:*:*:*:*:*:*:*

References