Cesanta

Mongoose

58 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 17:41:02
  • Zuletzt bearbeitet 20.08.2026 19:17:01

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_c...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:40:02
  • Zuletzt bearbeitet 20.08.2026 18:16:46

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The mg_ssi() function in src/ssi.c conca...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:39:16
  • Zuletzt bearbeitet 20.08.2026 20:17:46

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() pa...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:37:54
  • Zuletzt bearbeitet 20.08.2026 18:16:46

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() func...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:37:17
  • Zuletzt bearbeitet 20.08.2026 18:16:46

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The print...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:36:39
  • Zuletzt bearbeitet 20.08.2026 19:17:01

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and ...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:34:50
  • Zuletzt bearbeitet 20.08.2026 20:17:46

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bun...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:30:58
  • Zuletzt bearbeitet 20.08.2026 20:17:46

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_p...

  • EPSS 0.35%
  • Veröffentlicht 09.07.2026 15:13:40
  • Zuletzt bearbeitet 28.07.2026 03:16:43

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against t...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 25.04.2026 16:30:13
  • Zuletzt bearbeitet 29.04.2026 19:00:39

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verificat...