PT-2026-29692 · Cesanta · Cesanta Mongoose
The_Evilsocket
+1
·
Published
2026-04-02
·
Updated
2026-04-30
·
CVE-2026-5244
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cesanta Mongoose versions up to 7.20
Description
A flaw exists in the TLS 1.3 Handler component of Cesanta Mongoose, specifically within the
mg tls recv cert function in the mongoose.c file. Manipulation of the pubkey argument can lead to a heap-based buffer overflow, potentially allowing for remote attacks.Recommendations
Upgrade to version 7.21 or later.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cesanta Mongoose