VYPR

Mongoose

by Mongoose

Source repositories

CVEs (6)

  • CVE-2020-25887HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

  • CVE-2024-53900CriDec 2, 2024
    risk 0.52cvss 9.1epss 0.04

    Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

  • CVE-2025-51495HigSep 29, 2025
    risk 0.00cvss 7.5epss 0.00

    An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a…

  • CVE-2023-34188HigJun 23, 2023
    risk 0.00cvss 7.5epss 0.01

    The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other…

  • CVE-2019-13503HigJul 11, 2019
    risk 0.00cvss 7.5epss 0.01

    mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

  • CVE-2019-12951CriJun 24, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.