| Bug | Description |
|---|
| CVE-2026-73261 | Built-in TCP/IP malformed TCP option handling |
| CVE-2026-73260 | Built-in TLS X.509 DER parsing bounds check |
| CVE-2026-73259 | Mongoose is an embedded web server and network library. Prior to 7.22, ... |
| CVE-2026-73258 | Mongoose is an embedded web server and network library. Prior to 7.22, ... |
| CVE-2026-73257 | Mongoose is an embedded web server and network library. Priro to versi ... |
| CVE-2026-73256 | Mongoose is an embedded web server and network library. Prior to 7.22, ... |
| CVE-2026-73255 | Mongoose is an embedded web server and network library. Prior to 7.22, ... |
| CVE-2026-73254 | Mongoose is an embedded web server and network library. Prior to 7.22, ... |
| CVE-2026-73253 | Mongoose is an embedded web server and network library. Prior to versi ... |
| CVE-2026-73252 | Built-in TLS short-record handling |
| CVE-2026-73251 | Mongoose is an embedded web server and network library. Prior to 7.23, ... |
| CVE-2026-63626 | Built-in TCP/IP PPP IPV6CP option parsing bounds check |
| CVE-2026-52079 | ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall |
| CVE-2026-52078 | opendir() stack overflow via wcscat on MAX_PATH path |
| CVE-2026-52076 | cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset |
| CVE-2026-52075 | mg_random rand() fallback used for TLS secrets |
| CVE-2026-52073 | ppp_handle_ipcp attacker-controlled IPCP length -- OOB read |
| CVE-2026-52072 | mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read |
| CVE-2026-52071 | mg_tls_verify_cert_signature OOB read for short ECDSA integers |
| CVE-2026-52070 | rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read |
| CVE-2026-52069 | rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion |
| CVE-2026-52068 | rx_ndp_na NDP NA missing option length check -- OOB read |
| CVE-2026-52067 | rx_ip truncated DHCP options size_t underflow OOB read |
| CVE-2026-52066 | TLS certificate notAfter validated against hardcoded 2025-01-01 string |
| CVE-2026-52065 | mg_tls_client_recv_hello key_share extension OOB read |
| CVE-2026-52064 | DNS transaction ID is sequential -- enables response injection |
| CVE-2026-52062 | NDP RA allows any value for MTU |
| CVE-2026-52061 | mg_tls_recv_cert certificate chain length unchecked -- OOB read |
| CVE-2026-52060 | TLS certificate notAfter validated against hardcoded 2025-01-01 string |
| CVE-2026-52059 | RSA-PSS CertificateVerify checks only 0xbc trailer |
| CVE-2026-52058 | mg_der_to_tlv long-form DER length OOB read |
| CVE-2026-52057 | mg_der_find_oid unbounded recursion on constructed DER tags |
| CVE-2026-52056 | skip_chunk off-by-one OOB read in chunked HTTP CRLF check |
| CVE-2026-52055 | mg_der_to_tlv long-form DER length OOB read |
| CVE-2026-52054 | find_opt zero-length PPP option -- infinite loop |
| CVE-2026-52053 | rx_ip6 IPv6 extension header OOB read; 16-bit len wrap |
| CVE-2026-52052 | mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read |
| CVE-2026-52051 | mg_tls_server_recv_hello session_id_len OOB read |
| CVE-2026-52050 | precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM |
| CVE-2026-52048 | MQTT v5 properties bounds check uses relative offset against absolute position |
| CVE-2026-52047 | w5100_rx wraparound RX path copies n instead of r bytes |
| CVE-2026-11404 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ... |
| CVE-2026-6986 | A security vulnerability has been detected in Cesanta Mongoose up to 7 ... |
| CVE-2026-6985 | A weakness has been identified in Cesanta Mongoose up to 7.20. This vu ... |
| CVE-2026-5246 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affecte ... |
| CVE-2026-5245 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts ... |
| CVE-2026-5244 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This af ... |
| CVE-2026-2968 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impa ... |
| CVE-2026-2967 | A security vulnerability has been detected in Cesanta Mongoose up to 7 ... |
| CVE-2026-2966 | A weakness has been identified in Cesanta Mongoose up to 7.20. The imp ... |
| CVE-2025-65502 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before ... |
| CVE-2025-51495 | An integer overflow vulnerability exists in the WebSocket component of ... |
| CVE-2023-34188 | The HTTP server in Mongoose before 7.10 accepts requests containing ne ... |
| CVE-2023-2905 | Due to a failure in validating the length of a provided MQTT_CMD_PUBLI ... |
| CVE-2021-26530 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compile ... |
| CVE-2021-26529 | The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7- ... |
| CVE-2021-26528 | The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is ... |
| CVE-2020-25887 | Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when r ... |
| CVE-2020-25756 | A buffer overflow vulnerability exists in the mg_get_http_header funct ... |
| CVE-2019-19307 | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6. ... |
| CVE-2019-13503 | mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer o ... |
| CVE-2019-12951 | An issue was discovered in Mongoose before 6.15. The parse_mqtt() func ... |