VendorsCesantamongooseany version
Vulnerabilities

Cesanta Mongoose any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2018-20354
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Published 2019-06-10 · Modified
9.8EPSS 0.036
CVE-2018-20355
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Published 2019-06-10 · Modified
9.8EPSS 0.036
CVE-2018-20356
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Published 2019-06-10 · Modified
9.8EPSS 0.036
CVE-2018-20353
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.
Published 2019-06-10 · Modified
9.8EPSS 0.036
CVE-2019-12951
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.
Published 2019-06-24 · Modified
9.8EPSS 0.020
CVE-2022-25299
Arbitrary File Write
Published 2022-02-18 · Modified
9.8EPSS 0.014
CVE-2026-5244
Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow
Published 2026-04-02 · Analyzed
9.8EPSS 0.008
CVE-2024-42383
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
9.8EPSS 0.003
CVE-2021-26529
The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack via connection request after exhausting memory pool.
Published 2021-02-08 · Modified
9.1EPSS 0.015
CVE-2024-42386
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Modified
8.2EPSS 0.004
CVE-2026-5245
Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow
Published 2026-04-02 · Analyzed
8.1EPSS 0.006
CVE-2026-5246
Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization
Published 2026-04-02 · Analyzed
8.1EPSS 0.006
CVE-2023-34188
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Published 2023-06-23 · Modified
7.5EPSS 0.010
CVE-2026-6985
Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop
Published 2026-04-25 · Analyzed
7.5EPSS 0.009
CVE-2024-42384
Integer Overflow or Wraparound in Mongoose Web Server library
Published 2024-11-18 · Modified
7.5EPSS 0.005
CVE-2025-51495
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
Published 2025-09-29 · Analyzed
7.5EPSS 0.004
CVE-2024-42392
Improper Neutralization of Delimiters in Mongoose Web Server library
Published 2024-11-18 · Modified
7.5EPSS 0.002
CVE-2024-42385
Improper Neutralization of Delimiters in Mongoose Web Server library
Published 2024-11-18 · Modified
7.0EPSS 0.001
CVE-2024-42389
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
5.3EPSS 0.003
CVE-2024-42388
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
5.3EPSS 0.003
CVE-2024-42387
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
5.3EPSS 0.003
CVE-2024-42391
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Modified
5.3EPSS 0.003
CVE-2024-42390
Use of Out-of-range Pointer Offset in Mongoose Web Server library
Published 2024-11-18 · Analyzed
5.3EPSS 0.003
CVE-2025-65502
Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.
Published 2025-11-24 · Analyzed
4.3EPSS 0.003
CVE-2026-2967
Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
Published 2026-02-23 · Analyzed
3.7EPSS 0.007
CVE-2026-2966
Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values
Published 2026-02-23 · Analyzed
3.7EPSS 0.005
CVE-2026-2968
Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification
Published 2026-02-23 · Analyzed
3.7EPSS 0.003
CVE-2026-6986
Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
Published 2026-04-25 · Analyzed
3.7EPSS 0.003