CVE-2026-5246
- EPSS 0.06%
- Veröffentlicht 02.04.2026 09:45:11
- Zuletzt bearbeitet 03.04.2026 16:10:52
A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The atta...
CVE-2026-5245
- EPSS 0.08%
- Veröffentlicht 02.04.2026 09:00:19
- Zuletzt bearbeitet 03.04.2026 16:10:52
A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. ...
CVE-2026-5244
- EPSS 0.08%
- Veröffentlicht 02.04.2026 08:00:19
- Zuletzt bearbeitet 03.04.2026 16:10:52
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attac...
CVE-2018-25193
- EPSS 0.14%
- Veröffentlicht 06.03.2026 12:19:18
- Zuletzt bearbeitet 15.04.2026 14:53:58
Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data ...
CVE-2026-2968
- EPSS 0.02%
- Veröffentlicht 23.02.2026 03:02:07
- Zuletzt bearbeitet 23.02.2026 20:17:23
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verificatio...
CVE-2026-2967
- EPSS 0.22%
- Veröffentlicht 23.02.2026 02:32:07
- Zuletzt bearbeitet 23.02.2026 20:17:44
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a c...
CVE-2026-2966
- EPSS 0.16%
- Veröffentlicht 23.02.2026 02:02:08
- Zuletzt bearbeitet 23.02.2026 20:18:06
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insuffici...
CVE-2025-65502
- EPSS 0.25%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 12.12.2025 13:32:49
Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.
CVE-2025-51495
- EPSS 0.26%
- Veröffentlicht 29.09.2025 17:15:31
- Zuletzt bearbeitet 16.10.2025 17:00:47
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly...
CVE-2024-42390
- EPSS 0.33%
- Veröffentlicht 18.11.2024 10:15:08
- Zuletzt bearbeitet 19.11.2024 17:50:51
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.