CVE-2026-2966 describes a weakness in Cesanta Mongoose versions up to 7.20, specifically within the mg_sendnsreq function in /src/dns.c, where insufficient randomness in DNS transaction IDs can be generated. This vulnerability has a low CVSS score of 3.7, indicating a low potential impact (limited to integrity) with high attack complexity and remote exploitability. While public exploit code exists, the exploitability is considered difficult, and there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.20CPE matchmatch criteria | cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.