Cesanta
Cesanta Mongoose: vulnerabilidades y CVE
Cesanta Mongoose tiene 58 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 22 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE58
Últimos 12 meses19
Críticas22
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101003 | Media (5.5) | 0.46% | — | 28 sept 2026 | A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can… |
| CVE-2026-73259 | Media (5.4) | 0.41% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The… |
| CVE-2026-73258 | Media (6.5) | 0.46% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops… |
| CVE-2026-73257 | Crítica (9.1) | 0.67% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and… |
| CVE-2026-73256 | Crítica (9.1) | 0.44% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and… |
| CVE-2026-73255 | Media (6.5) | 0.66% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The… |
| CVE-2026-73254 | Media (5.4) | 0.34% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served… |
| CVE-2026-73253 | Crítica (9.1) | 0.34% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in… |
| CVE-2026-73251 | Crítica (9.3) | 0.19% | — | 20 ago 2026 | Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the… |
| CVE-2026-11404 | Alta (8.7) | 0.61% | — | 9 jul 2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index… |
| CVE-2026-6986 | Baja (2.9) | 0.25% | — | 25 abr 2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such… |
| CVE-2026-6985 | Media (5.5) | 0.92% | — | 25 abr 2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument… |
| CVE-2026-5246 | Baja (2.9) | 0.57% | — | 2 abr 2026 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to… |
| CVE-2026-5245 | Baja (2.9) | 0.62% | — | 2 abr 2026 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results… |
| CVE-2026-5244 | Media (5.5) | 0.76% | — | 2 abr 2026 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to… |
| CVE-2026-2968 | Baja (2.9) | 0.27% | — | 23 feb 2026 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation… |
| CVE-2026-2967 | Baja (2.9) | 0.70% | — | 23 feb 2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to… |
| CVE-2026-2966 | Baja (2.9) | 0.54% | — | 23 feb 2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the… |
| CVE-2025-65502 | Media (4.3) | 0.29% | — | 24 nov 2025 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL. |
| CVE-2025-51495 | Alta (7.5) | 0.43% | — | 29 sept 2025 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors… |
| CVE-2024-42392 | Alta (7.5) | 0.23% | — | 18 nov 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. |
| CVE-2024-42391 | Media (5.3) | 0.28% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42390 | Media (5.3) | 0.28% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42389 | Media (5.3) | 0.31% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42388 | Media (5.3) | 0.31% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42387 | Media (5.3) | 0.31% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |
| CVE-2024-42386 | Alta (7.5) | 0.38% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. |
| CVE-2024-42385 | Alta (7) | 0.10% | — | 18 nov 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. |
| CVE-2024-42384 | Alta (7.5) | 0.48% | — | 18 nov 2024 | Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. |
| CVE-2024-42383 | Crítica (9.8) | 0.27% | — | 18 nov 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.