CVE-2026-5244

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of the patch is 0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*

History

29 Apr 2026, 21:46

Type Values Removed Values Added
References () https://github.com/cesanta/mongoose/ - () https://github.com/cesanta/mongoose/ - Product
References () https://github.com/cesanta/mongoose/commit/0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1 - () https://github.com/cesanta/mongoose/commit/0d882f1b43ff2308b7486a56a9d60cd6dba8a3f1 - Patch
References () https://github.com/cesanta/mongoose/releases/tag/7.21 - () https://github.com/cesanta/mongoose/releases/tag/7.21 - Product, Release Notes
References () https://vuldb.com/submit/770063 - () https://vuldb.com/submit/770063 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354825 - () https://vuldb.com/vuln/354825 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354825/cti - () https://vuldb.com/vuln/354825/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:cesanta:mongoose:*:*:*:*:*:*:*:*
First Time Cesanta mongoose
Cesanta

02 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 08:16

Updated : 2026-04-29 21:46


NVD link : CVE-2026-5244

Mitre link : CVE-2026-5244

CVE.ORG link : CVE-2026-5244


JSON object : View

Products Affected

cesanta

  • mongoose
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow