Mongoose
by Cesanta
Source repositories
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-2966 | Low | 0.24 | 3.7 | 0.00 | Feb 23, 2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The… | ||
| CVE-2026-6986 | Low | 0.17 | 3.7 | 0.00 | Apr 25, 2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic… | ||
| CVE-2025-65502 | Med | 0.00 | 4.3 | 0.00 | Nov 24, 2025 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL. | ||
| CVE-2025-51495 | Hig | 0.00 | 7.5 | 0.00 | Sep 29, 2025 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a… | ||
| CVE-2023-2905 | Hig | 0.00 | 8.8 | 0.01 | Aug 9, 2023 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version… | ||
| CVE-2023-34188 | Hig | 0.00 | 7.5 | 0.01 | Jun 23, 2023 | The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other… | ||
| CVE-2022-25299 | Cri | 0.00 | 9.8 | 0.01 | Feb 18, 2022 | This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder. | ||
| CVE-2019-13503 | Hig | 0.00 | 7.5 | 0.01 | Jul 11, 2019 | mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read. | ||
| CVE-2019-12951 | Cri | 0.00 | 9.8 | 0.02 | Jun 24, 2019 | An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow. |
- risk 0.24cvss 3.7epss 0.00
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The…
- risk 0.17cvss 3.7epss 0.00
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic…
- risk 0.00cvss 4.3epss 0.00
Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.
- risk 0.00cvss 7.5epss 0.00
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a…
- risk 0.00cvss 8.8epss 0.01
Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…
- risk 0.00cvss 7.5epss 0.01
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other…
- risk 0.00cvss 9.8epss 0.01
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
- risk 0.00cvss 7.5epss 0.01
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
- risk 0.00cvss 9.8epss 0.02
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.
Page 3 of 3