CVE-2026-2303

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
Configurations

No configuration.

History

10 Feb 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 20:17

Updated : 2026-02-10 21:51


NVD link : CVE-2026-2303

Mitre link : CVE-2026-2303

CVE.ORG link : CVE-2026-2303


JSON object : View

Products Affected

No product.

CWE
CWE-183

Permissive List of Allowed Inputs