Information on source package mongoose

Available versions

ReleaseVersion
forky7.23+ds-1
sid7.23+ds-1

Resolved issues

BugDescription
CVE-2026-73261Built-in TCP/IP malformed TCP option handling
CVE-2026-73260Built-in TLS X.509 DER parsing bounds check
CVE-2026-73259Mongoose is an embedded web server and network library. Prior to 7.22, ...
CVE-2026-73258Mongoose is an embedded web server and network library. Prior to 7.22, ...
CVE-2026-73257Mongoose is an embedded web server and network library. Priro to versi ...
CVE-2026-73256Mongoose is an embedded web server and network library. Prior to 7.22, ...
CVE-2026-73255Mongoose is an embedded web server and network library. Prior to 7.22, ...
CVE-2026-73254Mongoose is an embedded web server and network library. Prior to 7.22, ...
CVE-2026-73253Mongoose is an embedded web server and network library. Prior to versi ...
CVE-2026-73252Built-in TLS short-record handling
CVE-2026-73251Mongoose is an embedded web server and network library. Prior to 7.23, ...
CVE-2026-63626Built-in TCP/IP PPP IPV6CP option parsing bounds check
CVE-2026-52079ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall
CVE-2026-52078opendir() stack overflow via wcscat on MAX_PATH path
CVE-2026-52076cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset
CVE-2026-52075mg_random rand() fallback used for TLS secrets
CVE-2026-52073ppp_handle_ipcp attacker-controlled IPCP length -- OOB read
CVE-2026-52072mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read
CVE-2026-52071mg_tls_verify_cert_signature OOB read for short ECDSA integers
CVE-2026-52070rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read
CVE-2026-52069rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion
CVE-2026-52068rx_ndp_na NDP NA missing option length check -- OOB read
CVE-2026-52067rx_ip truncated DHCP options size_t underflow OOB read
CVE-2026-52066TLS certificate notAfter validated against hardcoded 2025-01-01 string
CVE-2026-52065mg_tls_client_recv_hello key_share extension OOB read
CVE-2026-52064DNS transaction ID is sequential -- enables response injection
CVE-2026-52062NDP RA allows any value for MTU
CVE-2026-52061mg_tls_recv_cert certificate chain length unchecked -- OOB read
CVE-2026-52060TLS certificate notAfter validated against hardcoded 2025-01-01 string
CVE-2026-52059RSA-PSS CertificateVerify checks only 0xbc trailer
CVE-2026-52058mg_der_to_tlv long-form DER length OOB read
CVE-2026-52057mg_der_find_oid unbounded recursion on constructed DER tags
CVE-2026-52056skip_chunk off-by-one OOB read in chunked HTTP CRLF check
CVE-2026-52055mg_der_to_tlv long-form DER length OOB read
CVE-2026-52054find_opt zero-length PPP option -- infinite loop
CVE-2026-52053rx_ip6 IPv6 extension header OOB read; 16-bit len wrap
CVE-2026-52052mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read
CVE-2026-52051mg_tls_server_recv_hello session_id_len OOB read
CVE-2026-52050precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM
CVE-2026-52048MQTT v5 properties bounds check uses relative offset against absolute position
CVE-2026-52047w5100_rx wraparound RX path copies n instead of r bytes
CVE-2026-11404Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ...
CVE-2026-6986A security vulnerability has been detected in Cesanta Mongoose up to 7 ...
CVE-2026-6985A weakness has been identified in Cesanta Mongoose up to 7.20. This vu ...
CVE-2026-5246A vulnerability was determined in Cesanta Mongoose up to 7.20. Affecte ...
CVE-2026-5245A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts ...
CVE-2026-5244A vulnerability has been found in Cesanta Mongoose up to 7.20. This af ...
CVE-2026-2968A vulnerability was detected in Cesanta Mongoose up to 7.20. This impa ...
CVE-2026-2967A security vulnerability has been detected in Cesanta Mongoose up to 7 ...
CVE-2026-2966A weakness has been identified in Cesanta Mongoose up to 7.20. The imp ...
CVE-2025-65502Null pointer dereference in add_ca_certs() in Cesanta Mongoose before ...
CVE-2025-51495An integer overflow vulnerability exists in the WebSocket component of ...
CVE-2023-34188The HTTP server in Mongoose before 7.10 accepts requests containing ne ...
CVE-2023-2905Due to a failure in validating the length of a provided MQTT_CMD_PUBLI ...
CVE-2021-26530The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compile ...
CVE-2021-26529The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7- ...
CVE-2021-26528The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is ...
CVE-2020-25887Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when r ...
CVE-2020-25756A buffer overflow vulnerability exists in the mg_get_http_header funct ...
CVE-2019-19307An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6. ...
CVE-2019-13503mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer o ...
CVE-2019-12951An issue was discovered in Mongoose before 6.15. The parse_mqtt() func ...

Search for package or bug name: Reporting problems