Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5244

31
FAUCET Score

CVE-2026-5244 describes a high-severity heap-based buffer overflow vulnerability affecting Cesanta Mongoose versions up to 7.20, specifically in the TLS 1.3 Handler's mg_tls_recv_cert function. This flaw can be exploited remotely without authentication or user interaction, potentially leading to low impacts on confidentiality, integrity, and availability. The exploit has been publicly disclosed and is considered active, with community discussions highlighting potential for pre-authentication Remote Code Execution. Given the public availability of exploit details, immediate upgrade to Mongoose version 7.21 is strongly recommended to mitigate this critical risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0, < 7.21CPE matchmatch criteria
cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.73%
Probability of exploitation in next 30 days
EPSS Percentile
50.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0073 is in the 33rd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / cesanta/mongoose
Product
github.com / cesanta/mongoose/commit/0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1
Patch
github.com / cesanta/mongoose/releases/tag/7.21
ProductRelease Notes
vuldb.com / submit/770063
ExploitThird Party AdvisoryVDB Entry
vuldb.com / vuln/354825
Third Party AdvisoryVDB Entry
vuldb.com / vuln/354825/cti
Permissions RequiredVDB Entry