vciy

CVEs we hold for Cesanta

Records whose assigning authority named Cesanta as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-86716Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflowCesanta mJS
CVE-2026-73259Mongoose: Reflected XSS via decoded URI in directory listing rendercesanta mongoose
CVE-2026-73258Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipartcesanta mongoose
CVE-2026-73257Mongoose: Content-Length + Transfer-Encoding coexistence enables request smugglingcesanta mongoose
CVE-2026-73256Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TEcesanta mongoose
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file readcesanta mongoose
CVE-2026-73254Mongoose: Stored XSS via unescaped filenames in directory listingcesanta mongoose
CVE-2026-73253Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matchingcesanta mongoose
CVE-2026-73251Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verificationcesanta mongoose
CVE-2026-6986Cesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verificationCesanta Mongoose
CVE-2026-6985Cesanta Mongoose TCP Option net_builtin.c handle_opt infinite loopCesanta Mongoose
CVE-2026-5246Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorizationCesanta Mongoose
CVE-2026-5245Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflowCesanta Mongoose
CVE-2026-5244Cesanta Mongoose TLS 1.3 mongoose.c mg_tls_recv_cert heap-based overflowCesanta Mongoose
CVE-2026-2968Cesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verificationCesanta Mongoose
CVE-2026-2967Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of sourceCesanta Mongoose
CVE-2026-2966Cesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random valuesCesanta Mongoose
CVE-2026-11404Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID ParsingCesanta Mongoose
CVE-2025-0696no title heldCesanta Frozen
CVE-2025-0695no title heldCesanta Frozen
CVE-2024-42392Improper Neutralization of Delimiters in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42391Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42390Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42389Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42388Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42387Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42386Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42385Improper Neutralization of Delimiters in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42384Integer Overflow or Wraparound in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2024-42383Use of Out-of-range Pointer Offset in Mongoose Web Server libraryCesanta Mongoose Web Server
CVE-2023-2905Cesanta Mongoose MQTT Message Parsing Heap OverflowCesanta Mongoose
CVE-2022-25299Arbitrary File Writen/a cesanta/mongoose
CVE-2021-27425Cesanta Software Mongoose-OS Integer Overflow or WraparoundCesanta Software Mongoose-OS
CVE-2018-25193Mongoose Web Server 6.9 Denial of Service via Socket ConnectionCesanta Mongoose Web Server
CVE-2017-2922no title heldCesanta Mongoose
CVE-2017-2921no title heldCesanta Mongoose
CVE-2017-2909no title heldCesanta Mongoose
CVE-2017-2895no title heldCesanta Mongoose
CVE-2017-2894no title heldCesanta Mongoose
CVE-2017-2893no title heldCesanta Mongoose
CVE-2017-2892no title heldCesanta Mongoose
CVE-2017-2891no title heldCesanta Mongoose

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.