Skip to main content

Vendor/product archive

cesanta / mongoose CVEs

Beta · best-effort

47 CVEs tagged to cesanta / mongoose18 Critical, 11 High, 12 Medium, 6 Low, 0 Unrated.

CVE-2026-6986

Published Apr 25, 2026

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Au…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6985

Published Apr 25, 2026

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handle…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-5246

Published Apr 2, 2026

A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handl…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-5245

Published Apr 2, 2026

A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a ma…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-5244

Published Apr 2, 2026

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulatio…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-2968

Published Feb 23, 2026

A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authe…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2967

Published Feb 23, 2026

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Ha…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2966

Published Feb 23, 2026

A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-65502

Published Nov 24, 2025

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store(…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-51495

Published Sep 29, 2025

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the applicat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42392

Published Nov 18, 2024

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42391

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read uninten…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42390

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read uninten…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42389

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read uninten…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42388

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read uninten…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42387

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read uninten…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42386

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the a…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42385

Published Nov 18, 2024

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42384

Published Nov 18, 2024

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the appli…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42383

Published Nov 18, 2024

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25887

Published Aug 22, 2023

Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2905

Published Aug 9, 2023

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34188

Published Jun 23, 2023

The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25299

Published Feb 18, 2022

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26530

Published Feb 8, 2021

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection request after exhausting memo…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 47 CVEsPage 1 of 2