CVE-2026-5244 describes a high-severity heap-based buffer overflow vulnerability affecting Cesanta Mongoose versions up to 7.20, specifically in the TLS 1.3 Handler's mg_tls_recv_cert function. This flaw can be exploited remotely without authentication or user interaction, potentially leading to low impacts on confidentiality, integrity, and availability. The exploit has been publicly disclosed and is considered active, with community discussions highlighting potential for pre-authentication Remote Code Execution. Given the public availability of exploit details, immediate upgrade to Mongoose version 7.21 is strongly recommended to mitigate this critical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.21CPE matchmatch criteria | cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.