Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Mongoose — Vulnerabilities & Security Advisories 30

All 30 CVE vulnerabilities found in Mongoose, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Mongoose, a well-known web server and framework. It collects historical security advisories and weakness records for this specific product, covering a broad historical time range. Readers can use this resource to track the vendor's security posture, understand the prevalence of particular weakness classes such as buffer overflows, and review the complete vulnerability history of the Mongoose codebase.

Vendor: Cesanta

CVE ID Title CVSS Severity Published
CVE-2026-101003 Cesanta Mongoose MQTT Broker main.c fn stack-based overflow CWE-121 5.3 Medium 2026-09-28
CVE-2026-73253 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching CWE-295 9.1 Critical 2026-08-20
CVE-2026-73255 Mongoose: Path traversal in SSI #include directives enables arbitrary file read CWE-22 6.5 Medium 2026-08-20
CVE-2026-73259 Mongoose: Reflected XSS via decoded URI in directory listing render CWE-79 5.4 Medium 2026-08-20
CVE-2026-73256 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE CWE-444 9.1 Critical 2026-08-20
CVE-2026-73254 Mongoose: Stored XSS via unescaped filenames in directory listing CWE-79 5.4 Medium 2026-08-20
CVE-2026-73258 Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart CWE-697 6.5 Medium 2026-08-20
CVE-2026-73251 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification CWE-295 9.3 Critical 2026-08-20
CVE-2026-73257 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling CWE-444 9.1 Critical 2026-08-20
CVE-2026-73562 Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) CWE-1321 6.5 Medium 2026-08-13
CVE-2026-11404 Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing CWE-125 7.5 High 2026-07-09
CVE-2026-42334 Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection CWE-74 7.5 High 2026-05-14
CVE-2026-6986 Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification CWE-347 3.7 Low 2026-04-25
CVE-2026-6985 Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop CWE-835 5.3 Medium 2026-04-25
CVE-2026-5246 Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization CWE-639 5.6 Medium 2026-04-02
CVE-2026-5245 Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow CWE-121 5.6 Medium 2026-04-02
CVE-2026-5244 Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow CWE-122 7.3 High 2026-04-02
CVE-2026-2968 Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification CWE-347 3.7 Low 2026-02-23
CVE-2026-2967 Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source CWE-940 3.7 Low 2026-02-23
CVE-2026-2966 Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values CWE-330 3.7 Low 2026-02-23
CVE-2025-23061 Mongoose 代码注入漏洞 CWE-94 9.0 Critical 2025-01-15
CVE-2023-2905 Cesanta Mongoose MQTT Message Parsing Heap Overflow CWE-122 9.8 - 2023-08-09
CVE-2017-2891 Cesanta Mongoose 安全漏洞 9.8 - 2017-11-07
CVE-2017-2922 Cesanta Mongoose 安全漏洞 9.8 - 2017-11-07
CVE-2017-2921 Cesanta Mongoose 数字错误漏洞 9.8 - 2017-11-07
CVE-2017-2909 Cesanta Mongoose 安全漏洞 7.5 - 2017-11-07
CVE-2017-2895 Cesanta Mongoose 数字错误漏洞 9.1 - 2017-11-07
CVE-2017-2894 Cesanta Mongoose 缓冲区错误漏洞 9.8 - 2017-11-07
CVE-2017-2893 Cesanta Mongoose 安全漏洞 7.5 - 2017-11-07
CVE-2017-2892 Cesanta Mongoose 数字错误漏洞 9.8 - 2017-11-07

All 30 known CVE vulnerabilities affecting Mongoose with full Chinese analysis, references, and POCs where available.