PT-2026-21494 · Cesanta · Cesanta Mongoose

Dwbruijn

·

Published

2026-02-23

·

Updated

2026-04-30

·

CVE-2026-2967

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cesanta Mongoose versions prior to 7.21
Description A security issue exists in Cesanta Mongoose. The getpeer function within the TCP Sequence Number Handler component, located in /src/net builtin.c, does not properly verify the source of a communication channel. This allows for remote attacks with high complexity and difficult exploitability. The exploit has been publicly disclosed.
Recommendations Update to version 7.21 or later. As a temporary workaround, consider restricting access to the getpeer function until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-2967
JLSEC-2026-367

Affected Products

Cesanta Mongoose