{"schema_version":"1.7.5","id":"GHSA-cp6g-7hqx-qxhp","published":"2026-02-10T21:31:31Z","modified":"2026-07-24T19:11:24.645783033Z","aliases":["CVE-2026-2303","GO-2026-5327"],"related":["CGA-qpqr-6vcg-2g85"],"summary":"mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling","details":"The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.","affected":[{"package":{"name":"go.mongodb.org/mongo-driver","ecosystem":"Go","purl":"pkg:golang/go.mongodb.org/mongo-driver"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.17.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cp6g-7hqx-qxhp/GHSA-cp6g-7hqx-qxhp.json"}},{"package":{"name":"go.mongodb.org/mongo-driver/v2","ecosystem":"Go","purl":"pkg:golang/go.mongodb.org/mongo-driver/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cp6g-7hqx-qxhp/GHSA-cp6g-7hqx-qxhp.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2303"},{"type":"PACKAGE","url":"https://github.com/mongodb/mongo-go-driver"},{"type":"WEB","url":"https://jira.mongodb.org/browse/GODRIVER-3770"}],"database_specific":{"cwe_ids":["CWE-183"],"github_reviewed":true,"github_reviewed_at":"2026-06-18T13:02:29Z","nvd_published_at":"2026-02-10T20:17:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}