The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
Update go.mongodb.org/mongo-driver to 1.17.7; go.mongodb.org/mongo-driver/v2 to 2.4.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling affects go.mongodb.org/mongo-driver (go), go.mongodb.org/mongo-driver/v2 (go). Severity is medium. The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| go.mongodb.org/mongo-drivergo |
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
Update go.mongodb.org/mongo-driver to 1.17.7; go.mongodb.org/mongo-driver/v2 to 2.4.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanmongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling affects go.mongodb.org/mongo-driver (go), go.mongodb.org/mongo-driver/v2 (go). Severity is medium. The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
AI coding agents often install or upgrade packages automatically in go. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| go.mongodb.org/mongo-drivergo |
| <1.17.7 |
| 1.17.7 |
| go.mongodb.org/mongo-driver/v2go | <2.4.2 | 2.4.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <1.17.7 |
| 1.17.7 |
| go.mongodb.org/mongo-driver/v2go | <2.4.2 | 2.4.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard