PT-2026-7457 · Unknown · Mongodb Go Driver

CVE-2026-2303

·

Published

2026-02-10

·

Updated

2026-09-04

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions mongo-go-driver (affected versions not specified)
Description The software contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation has a heap out-of-bounds read issue because of incorrect assumptions about string termination in the GSSAPI standard. GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, which leads to reading one byte past the allocated heap buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-77525
AZL-77547
AZL-77559
BDU:2026-01861
CLEANSTART-2026-AD30368
CLEANSTART-2026-DS82965
CLEANSTART-2026-ES72297
CLEANSTART-2026-GX27419
CLEANSTART-2026-HD68184
CLEANSTART-2026-IE49312
CLEANSTART-2026-JW97006
CLEANSTART-2026-KQ90880
CLEANSTART-2026-LC55153
CLEANSTART-2026-LK99645
CLEANSTART-2026-LP13983
CLEANSTART-2026-MA24172
CLEANSTART-2026-RW78583
CLEANSTART-2026-TG12071
CLEANSTART-2026-TM08995
CLEANSTART-2026-UV44486
CLEANSTART-2026-VA62549
CLEANSTART-2026-ZZ38071
CVE-2026-2303
GHSA-CP6G-7HQX-QXHP
GO-2026-5327
OPENSUSE-SU-2026:11197-1
OPENSUSE-SU-2026:11684-1
OPENSUSE-SU-2026:21276-1
OPENSUSE-SU-2026:21551-1
SUSE-RU-2026:2815-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Mongodb Go Driver