Cesanta Mongoose vulnerabilities
64 known vulnerabilities affecting cesanta/mongoose.
Total CVEs
64
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH21MEDIUM12LOW4
Vulnerabilities
Page 3 of 4
CVE-2017-2909P3HIGHCVSS 7.5v6.82017-11-07
CVE-2017-2909 [HIGH] CWE-835 CVE-2017-2909: An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 li
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet over the network to trigger this vulnerability.
nvd
CVE-2023-34188P3HIGHCVSS 7.5fixed in 7.102023-06-23
CVE-2023-34188 [HIGH] CWE-1284 CVE-2023-34188: The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers.
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
nvd
CVE-2025-51495P3HIGHCVSS 7.5≥ 7.5, ≤ 7.172025-09-29
CVE-2025-51495 [HIGH] CWE-190 CVE-2025-51495: An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By se
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
nvd
CVE-2024-42384P3HIGHCVSS 7.5≤ 7.142024-11-18
CVE-2024-42384 [HIGH] CWE-190 CVE-2024-42384: Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
nvd
CVE-2023-3696P3CRITICAL≥ 7.0.0, < 7.3.3≥ 6.0.0, < 6.11.3+1 more2023-07-17
CVE-2023-3696 [CRITICAL] CWE-1321 Mongoose Prototype Pollution vulnerability
Mongoose Prototype Pollution vulnerability
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.
ghsaosv
CVE-2024-42392P3HIGHCVSS 7.5≤ 7.142024-11-18
CVE-2024-42392 [HIGH] CWE-140 CVE-2024-42392: Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to t
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.
nvd
CVE-2026-101003P3MEDIUMCVSS 5.3v7.0v7.1+20 more2026-09-28
CVE-2026-101003 [MEDIUM] CWE-119 CVE-2026-101003: A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and cou
nvd
CVE-2019-13503P4HIGHCVSS 7.5v6.152019-07-11
CVE-2019-13503 [HIGH] CWE-125 CVE-2019-13503: mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
nvd
CVE-2018-10945P4HIGHCVSS 7.5v6.112018-06-19
CVE-2018-10945 [HIGH] CWE-125 CVE-2018-10945: The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial
The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.
nvd
CVE-2026-73259P4MEDIUMCVSS 5.4fixed in 7.222026-08-20
CVE-2026-73259 [MEDIUM] CWE-79 CVE-2026-73259: Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1 elements without HTML entity enco
nvd
CVE-2026-73254P4MEDIUMCVSS 5.4fixed in 7.222026-08-20
CVE-2026-73254 [MEDIUM] CWE-79 CVE-2026-73254: Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the href but inserts the raw filesystem f
nvd
CVE-2024-42385P4HIGHCVSS 7.0≤ 7.142024-11-18
CVE-2024-42385 [HIGH] CWE-140 CVE-2024-42385: Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to t
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
nvd
CVE-2024-42389P4MEDIUMCVSS 5.3≤ 7.142024-11-18
CVE-2024-42389 [MEDIUM] CWE-823 CVE-2024-42389: Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an atta
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
nvd
CVE-2024-42388P4MEDIUMCVSS 5.3≤ 7.142024-11-18
CVE-2024-42388 [MEDIUM] CWE-823 CVE-2024-42388: Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an atta
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
nvd
CVE-2024-42387P4MEDIUMCVSS 5.3≤ 7.142024-11-18
CVE-2024-42387 [MEDIUM] CWE-823 CVE-2024-42387: Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an atta
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
nvd
CVE-2024-42391P4MEDIUMCVSS 5.3≤ 7.142024-11-18
CVE-2024-42391 [MEDIUM] CWE-823 CVE-2024-42391: Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an atta
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
nvd
CVE-2024-42390P4MEDIUMCVSS 5.3≤ 7.142024-11-18
CVE-2024-42390 [MEDIUM] CWE-823 CVE-2024-42390: Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an atta
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
nvd
CVE-2018-19587P4MEDIUMCVSS 6.5v6.132018-11-27
CVE-2018-19587 [MEDIUM] CWE-119 CVE-2018-19587: In Cesanta Mongoose 6.13, a SIGSEGV exists in the mongoose.c mg_mqtt_add_session() function.
In Cesanta Mongoose 6.13, a SIGSEGV exists in the mongoose.c mg_mqtt_add_session() function.
nvd
CVE-2026-2967P4LOWCVSS 3.7≤ 7.20v7.0+20 more2026-02-23
CVE-2026-2967 [LOW] CWE-940 CVE-2026-2967: A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The attack may be initiated remotely. The attack's complexity is rated as high. The
nvd
CVE-2026-2966P4LOWCVSS 3.7≤ 7.20v7.0+20 more2026-02-23
CVE-2026-2966 [LOW] CWE-310 CVE-2026-2966: A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack requires a high level of complexity. T
nvd