The Short Version
The evidence strongly supports this as the long-documented Cyrus SASL flaw CVE-2002-1347. Multiple independent advisories state that Cyrus SASL 2.1.9 and earlier are vulnerable to a buffer overflow triggered by long usernames during canonicalization. Conflicting references point to a separate 2026 MongoDB C Driver integration bug, not the library vulnerability described here.