Friday, Jul 24, 2026 The claims desk. Receipts included. POWERED BY LENZ
IsThis

TECH

The Claim

Cyrus SASL library versions 2.1.9 and earlier have a buffer overflow vulnerability that can be triggered by long inputs during user name canonicalization.

The Short Version

The evidence strongly supports this as the long-documented Cyrus SASL flaw CVE-2002-1347. Multiple independent advisories state that Cyrus SASL 2.1.9 and earlier are vulnerable to a buffer overflow triggered by long usernames during canonicalization. Conflicting references point to a separate 2026 MongoDB C Driver integration bug, not the library vulnerability described here.

Caveats

  • This describes a historical vulnerability from 2002-2003 that has long been patched in later releases.
  • Some advisories also list the older 1.5.24 branch as affected; the claim mentions only the 2.1.x range.
  • Do not confuse this library flaw with CVE-2026-6691, which affects MongoDB C Driver integration code rather than Cyrus SASL itself.

The Receipts

  1. CVE-2026-6691

    CVE.org

  2. Cyrus-SASL library username buffer overflow - CVE-2002-1347

    IBM X-Force Exchange

  3. DSA-180-1 cyrus-sasl - buffer overflow in username handling

    Debian

  4. CVE-2002-1347

    Red Hat

  5. CVE-2026-6691

    INCIBE-CERT

  6. VU#864643 Carnegie Mellon University Cyrus SASL vulnerable to buffer overflow

    CERT/CC Vulnerability Notes Database

  7. The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization

    GitHub

  8. CVE-2002-1347

    Debian Security Tracker

  9. Bug 79957 - security: buffer overflow in Cyrus SASL canonicalization function

    Red Hat Bugzilla

  10. Cyrus SASL username canonicalization buffer overflow vulnerability

    SecurityFocus

+ 15 more sources — see the full list on Lenz

Filed Under

Cyrus SASL

More Fact Checks