{"id":"CVE-2026-73258","title":"Mongoose is an embedded web server and network library","summary":"Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-697"],"vendor":"cesanta","product":"mongoose","affected":["mongoose < 7.22"],"published":"2026-08-20","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:19:49.197","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73258","references":[{"url":"https://github.com/cesanta/mongoose/commit/a9df523f76f43a38bd53b4232b9cfd4c16869e71","label":"security-advisories@github.com"},{"url":"https://github.com/cesanta/mongoose/pull/3611","label":"security-advisories@github.com"},{"url":"https://github.com/cesanta/mongoose/releases/tag/7.22","label":"security-advisories@github.com"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-cc55-8v3r-59p8","label":"security-advisories@github.com"},{"url":"https://github.com/cesanta/mongoose/security/advisories/GHSA-cc55-8v3r-59p8","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-20T18:32:20.304577Z"},"ingestedAt":"2026-09-10T20:16:33.036Z","epss":0.00323,"epssPercentile":0.25548,"slug":"CVE-2026-73258","body":"## Overview\n\nMongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when either character resembles part of a CRLF terminator. This truncates headers, filenames, or boundaries and can cause an application to accept dangerous content after seeing a misleading Content-Type value. This issue is fixed in version 7.22.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}