Vulnerabilities
Summary — last 7 days
New vulnerabilities2,564▼ 303 vs. last week
Critical / high1,351▲ 100 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
79 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Medium (5.8) | 0.24% | — | Opentelemetry Instrumentation Cassandra DriverAIOpentelemetry Instrumentation KnexAIOpentelemetry Instrumentation MongooseAIOpentelemetry Instrumentation MysqlAI+4 | 10/2/2026 | 10/2/2026 | OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose,… | |
| Deferred | Medium (5.5) | 0.46% | — | Cesanta MongooseAI | 9/28/2026 | 10/1/2026 | A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made… | |
| Analyzed | Medium (5.4) | 0.41% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1… | |
| Analyzed | Medium (6.5) | 0.46% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when… | |
| Analyzed | Critical (9.1) | 0.67% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and… | |
| Analyzed | Critical (9.1) | 0.44% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible… | |
| Analyzed | Medium (6.5) | 0.66% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The mg_ssi() function in src/ssi.c concatenates the directive argument into a filesystem path without calling… | |
| Analyzed | Medium (5.4) | 0.34% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the… | |
| Analyzed | Critical (9.1) | 0.34% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c… | |
| Analyzed | Critical (9.3) | 0.19% | — | Cesanta Mongoose | 8/20/2026 | 9/29/2026 | Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and… | |
| Awaiting Analysis | Medium (6.5) | 0.50% | — | MongooseAI | 8/13/2026 | 9/18/2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and… | |
| Deferred | High (8.7) | 0.61% | — | Cesanta MongooseAI | 7/9/2026 | 8/29/2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can… | |
| Analyzed | High (7.5) | 0.46% | — | Mongoosejs Mongoose | 5/14/2026 | 6/17/2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to… | |
| Analyzed | Low (2.9) | 0.25% | — | Cesanta Mongoose | 4/25/2026 | 6/17/2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from… | |
| Analyzed | Medium (5.5) | 0.92% | — | Cesanta Mongoose | 4/25/2026 | 6/17/2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The exploit has been… | |
| Analyzed | Low (2.9) | 0.57% | — | Cesanta Mongoose | 4/2/2026 | 6/17/2026 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. Attacks of this nature are highly… | |
| Analyzed | Low (2.9) | 0.62% | — | Cesanta Mongoose | 4/2/2026 | 6/17/2026 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of… | |
| Analyzed | Medium (5.5) | 0.76% | — | Cesanta Mongoose | 4/2/2026 | 6/17/2026 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Deferred | High (8.7) | 0.34% | — | Mongoose WEB ServerAI | 3/6/2026 | 6/17/2026 | Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unavailability. | |
| Analyzed | Low (2.9) | 0.27% | — | Cesanta Mongoose | 2/23/2026 | 6/17/2026 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely.… | |
| Analyzed | Low (2.9) | 0.70% | — | Cesanta Mongoose | 2/23/2026 | 6/17/2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The attack may be initiated remotely. The… | |
| Analyzed | Low (2.9) | 0.54% | — | Cesanta Mongoose | 2/23/2026 | 6/17/2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack… | |
| Analyzed | Medium (4.3) | 0.29% | — | Cesanta Mongoose | 11/24/2025 | 6/17/2026 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL. | |
| Analyzed | High (7.5) | 0.43% | — | Cesanta Mongoose | 9/29/2025 | 6/17/2026 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow. | |
| Analyzed | Critical (9.8) | 7.3% | — | Mongoosejs Mongoose | 1/15/2025 | 6/17/2026 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. |