Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/GODRIVER-3770 |
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb go Driver |
|
| Vendors & Products |
Mongodb
Mongodb go Driver |
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer. | |
| Title | Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak | |
| Weaknesses | CWE-183 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2026-02-11T15:16:15.789Z
Reserved: 2026-02-10T18:55:27.871Z
Link: CVE-2026-2303
Updated: 2026-02-11T15:16:11.659Z
Status : Deferred
Published: 2026-02-10T20:17:00.757
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-2303
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:30:15Z