Mongoose

Vendor:

First CVE: Nov 7, 2017 · Active for 8 years

48
Total CVEs
More Total CVEs than 97% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mongoose over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2017
8 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

CVE Severity & Scoring

Mongoose48 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.1%)
Network46 (95.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low41 (85.4%)
High7 (14.6%)
Unknown0 (0.0%)
User Interaction
None44 (91.7%)
Unknown0 (0.0%)
Required4 (8.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None48 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by send
Nov 26, 20199.851NONO
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a st
Nov 7, 20179.842NONO
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte fr
Jul 9, 20267.533NONO
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer der
Nov 7, 20177.532NONO
A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation
Apr 2, 20269.831NONO
An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13
Jun 10, 20199.831NONO
An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.1
Jun 10, 20199.831NONO
An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Libr
Jun 10, 20199.831NONO
An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server L
Jun 10, 20199.831NONO
An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.
Jun 24, 20199.830NONO

Exploit Exposure

Signals from CVEs in this product scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (48 CVEs).

Media Mentions

Signals from CVEs in this product scope (48 CVEs).

Top CNAs Publishing CVEs For Mongoose

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1018.81.0%00
7.039.11.5%00
6.889.08.6%00
6.1829.31.1%00
6.1619.841.6%00
6.1517.51.4%00
6.1338.21.5%00
6.1117.51.4%00