High severity7.5NVD Advisory· Published Apr 10, 2017· Updated May 13, 2026
CVE-2017-7185
CVE-2017-7185
Description
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.
Affected products
2- cpe:2.3:a:cesanta:mongoose_embedded_web_server_library:*:*:*:*:*:*:*:*Range: <=6.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/cesanta/mongoose-os/commit/042eb437973a202d00589b13d628181c6de5cf5bnvdPatchThird Party Advisory
- github.com/cesanta/mongoose/commit/b8402ed0733e3f244588b61ad5fedd093e3cf9ccnvdPatchThird Party Advisory
- www.compass-security.com/fileadmin/Datein/Research/Advisories/CVE-2017-7185_mongoose_os_use_after_free.txtnvdExploitTechnical DescriptionThird Party Advisory
- www.securityfocus.com/bid/97370nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/540355/100/0/threadednvd
- www.exploit-db.com/exploits/41826/nvd
News mentions
0No linked articles in our index yet.