Critical severity9.8NVD Advisory· Published Nov 7, 2017· Updated May 13, 2026
CVE-2017-2891
CVE-2017-2891
Description
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0398nvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.