Security: cesanta/mongoose
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Built-in TLS: CA-bundle certificate chain accepted without any signature verificationGHSA-qj6j-2692-v2r8 published
Aug 12, 2026 by scaprileHigh -
Unauthenticated remote heap out-of-bounds read in built-in TLS: off-by-one length check in mg_tls_recv_record() underflows recv_len to SIZE_MAXGHSA-hq58-98f5-2wg3 published
Aug 12, 2026 by scaprileHigh -
Out-of-bounds Read via length-counter underflow in built-in TLS X.509 DER parserGHSA-f6wr-mg35-p25g published
Aug 12, 2026 by scaprileHigh -
Loop with Unreachable Exit Condition ('Infinite Loop') in cesanta/mongooseGHSA-w626-q3p2-8762 published
Jul 10, 2026 by cpqModerate -
ppp_handle_ipv6cp() uses attacker-controlled length without bounds check — OOB read and heap overflow (PPP/PPPoE, MG_ENABLE_IPV6)GHSA-pc66-j6r6-49x9 published
Aug 12, 2026 by scaprileHigh -
handle_opt() missing opts[1] > len check — 1-byte OOB read corrupts TCP MSS, silences mg_send() per connectionGHSA-3fmr-92g4-wchx published
Aug 12, 2026 by scaprileHigh -
Reflected XSS via decoded URI in directory listing renderGHSA-9cwm-487w-h25w published
Aug 12, 2026 by scaprileModerate -
Multipart boundary/header scan logic error in mg_http_next_multipartGHSA-cc55-8v3r-59p8 published
Aug 12, 2026 by scaprileModerate -
Content-Length + Transfer-Encoding coexistence enables request smugglingGHSA-5wfq-r6mr-wqp6 published
Aug 12, 2026 by scaprileCritical -
HTTP/1.0 detection off-by-one enables request smuggling via chunked TEGHSA-mgp5-rjrv-h5j3 published
Aug 12, 2026 by scaprileCritical
Learn more about advisories related to cesanta/mongoose in the GitHub Advisory Database