CVE-2026-101003
published 2026-09-28CVE-2026-101003: A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c…
PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.46%
38.0th percentile
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
| cesanta | mongoose | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A weakness has been identified in Cesanta Mongoose up to 7.21.
ghsa_unreviewed·2026-09-28
CVE-2026-101003 [MEDIUM] CWE-119 A weakness has been identified in Cesanta Mongoose up to 7.21.
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.
VulDB
Cesanta Mongoose up to 7.21 MQTT Broker main.c fn stack-based overflow
vuldb·2026-09-27
CVE-2026-101003 [LOW] Cesanta Mongoose up to 7.21 MQTT Broker main.c fn stack-based overflow
A vulnerability classified as problematic was found in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-101003. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
Red Hat
mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
vendor_redhat·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CWE-787 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
A flaw was found in Mongoose. A remote attacker can trigger a stack-based buffer overflow by sending specially crafted network messages to the MQTT broker component. This flaw could lead to a Denial of Service (DoS) condition by crashing the application.
Statement: This vulnerability is evaluated as having Moderate impact for Red Hat because, although triggered remotely over network inputs without authentication, the scope of impact is limited to a denial of service crash and targets demonstration code rather than core platform functionality. The flawed broker logic resides within upstream tutorial files that are not deployed or enabled in supported Red Hat products. Any potential risk is confined to spe
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-101003 flmsg: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
bugzilla·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CVE-2026-101003 flmsg: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
CVE-2026-101003 flmsg: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b
Bugzilla
CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
bugzilla·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.
Bugzilla
CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [epel-all]
bugzilla·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [epel-all]
CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53
Bugzilla
CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
bugzilla·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
CVE-2026-101003 mongoose: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd
Bugzilla
CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
bugzilla·2026-09-28·CVSS 5.3
CVE-2026-101003 [MEDIUM] CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
CVE-2026-101003 smplayer: mongoose: Denial of Service via stack-based buffer overflow in MQTT broker [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd
https://github.com/cesanta/mongoose/https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71https://github.com/cesanta/mongoose/releases/tag/7.22https://vuldb.com/cve/CVE-2026-101003https://vuldb.com/submit/920005https://vuldb.com/vuln/410873https://vuldb.com/vuln/410873/cti
2026-09-28
Published