Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mongoose — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Mongoose, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerabilities associated with Mongoose, a popular open-source embedded HTTP server library developed by Cesanta, categorized under common weakness types such as buffer overflows and input validation errors. It aggregates security issues identified in Mongoose versions ranging from early releases through recent iterations, providing a comprehensive historical record of security flaws affecting this specific software component. Readers can use this resource to track vendor advisories issued by Cesanta regarding critical security patches, understand the mechanics and impact of specific weakness classes within the context of embedded web servers, and look up a product's vulnerability history to assess risk exposure over time. The content focuses exclusively on technical details and timeline data, excluding promotional material or subjective commentary. By consolidating information from multiple sources, including Common Vulnerabilities and Exposures databases and official release notes, this aggregation offers a neutral view of the security landscape surrounding Mongoose. Users interested in secure coding practices or maintaining legacy systems can reference this data to identify patterns in defect types and prioritize remediation efforts based on the severity and prevalence of reported issues. The page serves as a reference point for developers, security analysts, and system administrators seeking to evaluate the integrity and maintenance status of Mongoose deployments in their environments.

Vendor: Cesanta

CVE IDTitleCVSSSeverityPublished
CVE-2026-11404 Cesanta Mongoose before 7.22 Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing CWE-125 7.5 High2026-07-09
CVE-2026-42334 Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection CWE-74 7.5 High2026-05-14
CVE-2026-6986 Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification CWE-347 3.7 Low2026-04-25
CVE-2026-6985 Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop CWE-835 5.3 Medium2026-04-25
CVE-2026-5246 Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization CWE-639 5.6 Medium2026-04-02
CVE-2026-5245 Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow CWE-121 5.6 Medium2026-04-02
CVE-2026-5244 Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow CWE-122 7.3 High2026-04-02
CVE-2026-2968 Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification CWE-347 3.7 Low2026-02-23
CVE-2026-2967 Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source CWE-940 3.7 Low2026-02-23
CVE-2026-2966 Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values CWE-330 3.7 Low2026-02-23
CVE-2025-23061 Mongoose 代码注入漏洞 CWE-94 9.0 Critical2025-01-15
CVE-2023-2905 Cesanta Mongoose MQTT Message Parsing Heap Overflow CWE-122 9.8 -2023-08-09
CVE-2017-2891 Cesanta Mongoose 安全漏洞 9.8 -2017-11-07
CVE-2017-2922 Cesanta Mongoose 安全漏洞 9.8 -2017-11-07
CVE-2017-2921 Cesanta Mongoose 数字错误漏洞 9.8 -2017-11-07
CVE-2017-2909 Cesanta Mongoose 安全漏洞 7.5 -2017-11-07
CVE-2017-2895 Cesanta Mongoose 数字错误漏洞 9.1 -2017-11-07
CVE-2017-2894 Cesanta Mongoose 缓冲区错误漏洞 9.8 -2017-11-07
CVE-2017-2893 Cesanta Mongoose 安全漏洞 7.5 -2017-11-07
CVE-2017-2892 Cesanta Mongoose 数字错误漏洞 9.8 -2017-11-07

All 20 known CVE vulnerabilities affecting Mongoose with full Chinese analysis, references, and POCs where available.