Known Vulnerabilities for Mongoose by Cesanta

Listed below are 10 of the newest known vulnerabilities associated with "Mongoose" by "Cesanta".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-5246 A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the f... Not Provided 2026-04-02 2026-04-02
CVE-2026-5245 A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c... Not Provided 2026-04-02 2026-04-02
CVE-2026-5244 A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoos... Not Provided 2026-04-02 2026-04-02
CVE-2021-26530 The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB wri... 9.1 - CRITICAL 2021-02-08 2021-02-12
CVE-2021-26529 The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to r... 9.1 - CRITICAL 2021-02-08 2021-02-12
CVE-2021-26528 The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection r... 9.1 - CRITICAL 2021-02-08 2021-02-12
CVE-2020-25887 Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file. 8.8 - HIGH 2023-08-22 2023-08-25
CVE-2020-25756 ** DISPUTED ** A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a la... 9.8 - CRITICAL 2020-09-18 2023-11-07
CVE-2019-19307 An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite l... 9.8 - CRITICAL 2019-11-26 2020-08-24
CVE-2019-13503 mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read. 7.5 - HIGH 2019-07-11 2023-01-30

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCesantaMongoose7.1AllAllAll
ApplicationCesantaMongoose7.0AllAllAll
ApplicationCesantaMongoose6.9AllAllAll
ApplicationCesantaMongoose6.8AllAllAll
ApplicationCesantaMongoose6.7AllAllAll
ApplicationCesantaMongoose6.6AllAllAll
ApplicationCesantaMongoose6.5AllAllAll
ApplicationCesantaMongoose6.4AllAllAll
ApplicationCesantaMongoose6.3AllAllAll
ApplicationCesantaMongoose6.2AllAllAll
ApplicationCesantaMongoose6.18AllAllAll
ApplicationCesantaMongoose6.17AllAllAll
ApplicationCesantaMongoose6.16AllAllAll
ApplicationCesantaMongoose6.15AllAllAll
ApplicationCesantaMongoose6.14AllAllAll
ApplicationCesantaMongoose6.13AllAllAll
ApplicationCesantaMongoose6.12AllAllAll
ApplicationCesantaMongoose6.11AllAllAll
ApplicationCesantaMongoose6.10AllAllAll
ApplicationCesantaMongoose6.1AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report