CVE-2026-2303

ADVISORY - github

Summary

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.

EPSS Score: 0.00223 (0.127)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Permissive List of Allowed Inputs

ADVISORY - github

Permissive List of Allowed Inputs


NIST

CREATED

UPDATED

ADVISORY IDCVE-2026-2303
EXPLOITABILITY SCORE

2.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.9medium

GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

2.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.9medium