Cyrus SASL library versions 2.1.9 and earlier have a buffer overflow vulnerability that can be triggered by long inputs during user name canonicalization.
NOT BSTOTAL BS
NOT BS — Verdict: True
Verified by Lenz ·
The Short Version
The evidence strongly supports this as the long-documented Cyrus SASL flaw CVE-2002-1347. Multiple independent advisories state that Cyrus SASL 2.1.9 and earlier are vulnerable to a buffer overflow triggered by long usernames during canonicalization. Conflicting references point to a separate 2026 MongoDB C Driver integration bug, not the library vulnerability described here.
Caveats
This describes a historical vulnerability from 2002-2003 that has long been patched in later releases.
Some advisories also list the older 1.5.24 branch as affected; the claim mentions only the 2.1.x range.
Do not confuse this library flaw with CVE-2026-6691, which affects MongoDB C Driver integration code rather than Cyrus SASL itself.