VulnSea

mongoose vulnerabilities

CVEs whose affected-version data names the mongoose package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-73251Critical· 9.3
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function s…

Midnightcesanta · mongooseEPSS 0.19%via NVD
CVE-2026-73258Medium· 6.5PoC
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s…

Twilightcesanta · mongooseEPSS 0.32%via NVD
GHSA-664h-wqgq-64gwMedium· 6.5
2mo ago

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

Sunlitmongoose · mongoosevia GHSA
CVE-2024-42392Medium· 4.0
1y ago

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Sunlitcesanta · mongooseEPSS 0.23%via NVD
CVE-2024-42391Medium· 4.3
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Sunlitcesanta · mongooseEPSS 0.28%via NVD
CVE-2024-42386High· 8.2
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Twilightcesanta · mongooseEPSS 0.38%via NVD
CVE-2024-42385Medium· 4.0
1y ago

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Sunlitcesanta · mongooseEPSS 0.10%via NVD
CVE-2024-42384High· 7.5
1y ago

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Twilightcesanta · mongooseEPSS 0.48%via NVD
mongoose vulnerabilities (CVEs) · VulnSea