VYPR
Vendor

Mongoose

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2017-11567HigSep 7, 2017
    risk 0.61cvss 8.8epss 0.04

    Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code…

  • CVE-2020-25887HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

  • CVE-2018-25193HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources…

  • CVE-2025-51495HigSep 29, 2025
    risk 0.00cvss 7.5epss 0.00

    An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a…

  • CVE-2019-13503HigJul 11, 2019
    risk 0.00cvss 7.5epss 0.01

    mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

  • CVE-2019-12951CriJun 24, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.