VulnSea

Cesanta has 8 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The median CVSS is 6.9 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: mongoose (7), mJS (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.9
Publish → KEV
Last 90 days
3 prev 0

Products

  • mongoose 7
  • mJS 1
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Cesanta vulnerabilities

CVEs affecting Cesanta, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-86716High· 7.3PoC
2w ago

A vulnerability was determined in Cesanta mJS up to 1.26

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. …

MidnightCesanta · mJSEPSS 0.35%via NVD
CVE-2026-73251Critical· 9.3
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function s…

Midnightcesanta · mongooseEPSS 0.19%via NVD
CVE-2026-73258Medium· 6.5PoC
1mo ago

Mongoose is an embedded web server and network library

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s…

Twilightcesanta · mongooseEPSS 0.32%via NVD
CVE-2024-42392Medium· 4.0
1y ago

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Sunlitcesanta · mongooseEPSS 0.23%via NVD
CVE-2024-42391Medium· 4.3
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

Sunlitcesanta · mongooseEPSS 0.28%via NVD
CVE-2024-42386High· 8.2
1y ago

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Twilightcesanta · mongooseEPSS 0.38%via NVD
CVE-2024-42385Medium· 4.0
1y ago

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Sunlitcesanta · mongooseEPSS 0.10%via NVD
CVE-2024-42384High· 7.5
1y ago

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.

Twilightcesanta · mongooseEPSS 0.48%via NVD
Cesanta vulnerabilities (CVEs) · VulnSea