VYPR
High severity8.8NVD Advisory· Published Aug 9, 2023· Updated Jun 17, 2026

CVE-2023-2905

CVE-2023-2905

Description

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Cesanta/Mongoose3 versions
    cpe:2.3:a:cesanta:mongoose:7.10:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cesanta:mongoose:7.10:*:*:*:*:*:*:*
    • (no CPE)range: <=7.10, >=7.11
    • (no CPE)range: 7.10

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.