Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cesanta

First CVE: Apr 10, 2017Active for: 9 yearsTotal CVEs: 137
40.4
VTI Score
High

Cesanta develops a narrowly focused set of embedded networking and IoT products—most notably the Mongoose web server library and Mongoose OS—that sit deep in firmware and resource-constrained devices, despite the vendor's modest product count. Vulnerabilities affecting Cesanta's portfolio skew toward serious outcomes, with a meaningful share reaching critical severity, though the small absolute footprint and specialized deployment context mean the vendor does not dominate broad risk rankings. The exposure recurs across the Mongoose family through memory-safety weaknesses including out-of-bounds writes and NULL-pointer dereferences, alongside control-flow issues such as uncontrolled recursion, reflecting the C-language implementation and parsing demands of an embedded web server stack. Defenders deploying Cesanta's components in production firmware or edge devices should treat advisories as high-priority for their specific installations, particularly where firmware updates are infrequent; current severity and exploitation status are shown alongside this summary.

FAUCET AI Generated
137
Total CVEs
More Total CVEs than 99% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cesanta over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2017
9 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (137 CVEs).

137 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19307CRITICAL
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by send
Nov 26, 20199.851NONO
CVE-2017-2894CRITICAL
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a st
Nov 7, 20179.842NONO
CVE-2017-7185HIGH
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 a
Apr 10, 20177.542NOYES
CVE-2017-11567HIGH
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.co
Sep 7, 20178.841NOYES
CVE-2026-11404HIGH
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte fr
Jul 9, 20267.533NONO
CVE-2017-2893HIGH
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer der
Nov 7, 20177.532NONO
CVE-2026-5244CRITICAL
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation
Apr 2, 20269.831NONO
CVE-2021-27425CRITICAL
Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting
May 3, 20229.831NONO
CVE-2018-20356CRITICAL
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13
Jun 10, 20199.831NONO
CVE-2018-20355CRITICAL
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.1
Jun 10, 20199.831NONO
View all 137 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products137 CVEs
52%
28%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local75 (54.7%)
Network61 (44.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.7%)
Attack Complexity
Low130 (94.9%)
High7 (5.1%)
Unknown0 (0.0%)
User Interaction
None59 (43.1%)
Unknown0 (0.0%)
Required78 (56.9%)
Privileges Required
Low5 (3.6%)
High0 (0.0%)
None132 (96.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (137 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cesanta.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cesanta — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cesanta's Products

View all 8 CNAs →

Top CWEs