VendorsCesantamongooseall versions
Vulnerabilities

Cesanta Mongoose

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2024-42391
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Modified
5.3EPSS 0.003
CVE-2024-42390
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
5.3EPSS 0.003
CVE-2025-65502
Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2026-2967
Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
Published 2026-02-23 · Analyzed
3.7EPSS 0.007
CVE-2026-2966
Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values
Published 2026-02-23 · Analyzed
3.7EPSS 0.005
CVE-2026-2968
Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification
Published 2026-02-23 · Analyzed
3.7EPSS 0.003
CVE-2026-6986
Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
Published 2026-04-25 · Analyzed
3.7EPSS 0.003
← Prev2 / 2