Cesanta Mongoose vulnerabilities
64 known vulnerabilities affecting cesanta/mongoose.
Total CVEs
64
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL27HIGH21MEDIUM12LOW4
Vulnerabilities
Page 4 of 4
CVE-2026-2968P4LOWCVSS 3.7≤ 7.20v7.0+20 more2026-02-23
CVE-2026-2968 [LOW] CWE-345 CVE-2026-2968: A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_p
A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely. This attack is characterized by high co
nvd
CVE-2025-65502P4MEDIUMCVSS 4.3fixed in 7.22025-11-24
CVE-2025-65502 [MEDIUM] CWE-476 CVE-2025-65502: Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to
Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.
nvd
CVE-2026-6986P4LOWCVSS 3.7≥ 7.0, < 7.21v7.0+20 more2026-04-25
CVE-2026-6986 [LOW] CWE-345 CVE-2026-6986: A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the fu
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from remote. A high complexity level is associ
nvd
CVE-2022-24304CRITICAL≥ 6.0.0, < 6.4.6≥ 0, < 5.13.152022-08-27
CVE-2022-24304 [CRITICAL] CWE-1321 Mongoose Vulnerable to Prototype Pollution in Schema Object
Mongoose Vulnerable to Prototype Pollution in Schema Object
### Description
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.
Affected versions of this package are vulnerable to Prototype Pollution. The `Schema.path()` function is vulnerable to prototype pollution when setting the `schema` object. This vulnerability allows modification of the Object prototype
ghsaosv
← Previous4 / 4