Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mongoose — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in Mongoose, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known Common Weakness Enumerations (CWEs) associated with the Mongoose web server product, managed by Embedded Artistics. It aggregates security reports and advisory data spanning from the product’s initial releases through recent updates, ensuring a comprehensive historical perspective on its security posture. Users can track vendor advisories to stay informed about critical fixes, understand the specific characteristics of recurring weakness classes affecting this software, and look up the product’s vulnerability history to assess risk over time. The collected data includes details on memory safety issues, input validation flaws, and other common web server vulnerabilities that have been identified in various versions of Mongoose. By centralizing this information, the page aims to provide developers and security analysts with a clear view of the product’s evolution regarding security practices. This resource does not cover third-party extensions or unrelated projects, focusing strictly on the core Mongoose implementation. The information is compiled from official vendor statements, independent security research, and public databases. Readers are encouraged to cross-reference this data with the latest official documentation for the most current mitigation strategies and patch availability.

Vendor: Cesanta

CVE ID Title CVSS Severity Published
CVE-2026-73253 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching CWE-295 9.1 Critical 2026-08-20
CVE-2026-73255 Mongoose: Path traversal in SSI #include directives enables arbitrary file read CWE-22 6.5 Medium 2026-08-20
CVE-2026-73259 Mongoose: Reflected XSS via decoded URI in directory listing render CWE-79 5.4 Medium 2026-08-20
CVE-2026-73256 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE CWE-444 9.1 Critical 2026-08-20
CVE-2026-73254 Mongoose: Stored XSS via unescaped filenames in directory listing CWE-79 5.4 Medium 2026-08-20
CVE-2026-73258 Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart CWE-697 6.5 Medium 2026-08-20
CVE-2026-73251 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification CWE-295 9.3 Critical 2026-08-20
CVE-2026-73257 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling CWE-444 9.1 Critical 2026-08-20
CVE-2026-73562 Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) CWE-1321 6.5 Medium 2026-08-13
CVE-2026-11404 Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing CWE-125 7.5 High 2026-07-09
CVE-2026-42334 Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection CWE-74 7.5 High 2026-05-14
CVE-2026-6986 Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification CWE-347 3.7 Low 2026-04-25
CVE-2026-6985 Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop CWE-835 5.3 Medium 2026-04-25
CVE-2026-5246 Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization CWE-639 5.6 Medium 2026-04-02
CVE-2026-5245 Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow CWE-121 5.6 Medium 2026-04-02
CVE-2026-5244 Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflow CWE-122 7.3 High 2026-04-02
CVE-2026-2968 Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification CWE-347 3.7 Low 2026-02-23
CVE-2026-2967 Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source CWE-940 3.7 Low 2026-02-23
CVE-2026-2966 Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values CWE-330 3.7 Low 2026-02-23
CVE-2025-23061 Mongoose 代码注入漏洞 CWE-94 9.0 Critical 2025-01-15
CVE-2023-2905 Cesanta Mongoose MQTT Message Parsing Heap Overflow CWE-122 9.8 - 2023-08-09
CVE-2017-2891 Cesanta Mongoose 安全漏洞 9.8 - 2017-11-07
CVE-2017-2922 Cesanta Mongoose 安全漏洞 9.8 - 2017-11-07
CVE-2017-2921 Cesanta Mongoose 数字错误漏洞 9.8 - 2017-11-07
CVE-2017-2909 Cesanta Mongoose 安全漏洞 7.5 - 2017-11-07
CVE-2017-2895 Cesanta Mongoose 数字错误漏洞 9.1 - 2017-11-07
CVE-2017-2894 Cesanta Mongoose 缓冲区错误漏洞 9.8 - 2017-11-07
CVE-2017-2893 Cesanta Mongoose 安全漏洞 7.5 - 2017-11-07
CVE-2017-2892 Cesanta Mongoose 数字错误漏洞 9.8 - 2017-11-07

All 29 known CVE vulnerabilities affecting Mongoose with full Chinese analysis, references, and POCs where available.