Cesanta develops a narrowly focused set of embedded networking and IoT products—most notably the Mongoose web server library and Mongoose OS—that sit deep in firmware and resource-constrained devices, despite the vendor's modest product count. Vulnerabilities affecting Cesanta's portfolio skew toward serious outcomes, with a meaningful share reaching critical severity, though the small absolute footprint and specialized deployment context mean the vendor does not dominate broad risk rankings. The exposure recurs across the Mongoose family through memory-safety weaknesses including out-of-bounds writes and NULL-pointer dereferences, alongside control-flow issues such as uncontrolled recursion, reflecting the C-language implementation and parsing demands of an embedded web server stack. Defenders deploying Cesanta's components in production firmware or edge devices should treat advisories as high-priority for their specific installations, particularly where firmware updates are infrequent; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cesanta over time
Signals from CVEs in this vendor scope (137 CVEs).
137 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19307CRITICAL An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by send | Nov 26, 2019 | 9.8 | 51 | NO | NO |
CVE-2017-2894CRITICAL An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a st | Nov 7, 2017 | 9.8 | 42 | NO | NO |
CVE-2017-7185HIGH Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 a | Apr 10, 2017 | 7.5 | 42 | NO | YES |
CVE-2017-11567HIGH Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.co | Sep 7, 2017 | 8.8 | 41 | NO | YES |
CVE-2026-11404HIGH Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte fr | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2017-2893HIGH An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer der | Nov 7, 2017 | 7.5 | 32 | NO | NO |
CVE-2026-5244CRITICAL A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation | Apr 2, 2026 | 9.8 | 31 | NO | NO |
CVE-2021-27425CRITICAL Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting | May 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-20356CRITICAL An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 | Jun 10, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-20355CRITICAL An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.1 | Jun 10, 2019 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (137 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cesanta.
Media articles that mention a CVE ID that affects a product developed by Cesanta — matched by CVE ID, not by vendor name.